Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The documentation explicitly instructs users to save the returned api_key and later prints the API Key to stdout in the workflow example, without any warning about credential sensitivity or safer handling. This increases the chance of accidental exposure through terminal history, logs, screen sharing, CI output, or shell transcripts, which could let others submit as the agent.
