Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The README explicitly recommends supplying the API key ID and secret on the command line. Command-line arguments are commonly exposed through shell history, process listings, audit logs, CI logs, and terminal recording tools, which can leak long-lived credentials to other local users or operational systems.
