Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The guide instructs users to set long-lived access keys directly on the command line and in environment variables without warning that shell history, terminal logging, process inspection, and inherited environments can expose those credentials. In a cloud administration context, leaked AK/SK pairs could permit unauthorized access to Huawei Cloud resources well beyond this read-only DCS use case.
