Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill directs users to place a live API credential in a local `.env` file but provides no guidance about secret handling, such as keeping `.env` out of version control, avoiding logging or screenshots, and using a secret manager in shared or production environments. In onboarding flows, users often copy instructions verbatim, so omission of these safeguards can lead to accidental credential exposure and unauthorized use of the Firecrawl account.
