Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The guide instructs users to configure long-lived access keys and secret keys directly in the CLI or shell environment without any warning about secure storage, least privilege, rotation, or avoiding shell history/process exposure. In a skill used for cloud inventory, this increases the chance of credential leakage and account compromise if copied into shared terminals, scripts, logs, or screenshots.
