Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The documentation repeatedly demonstrates direct token usage but provides no warning about secret handling, redaction, or avoiding hardcoding in source, prompts, and logs. In an agent setting, this can normalize unsafe credential practices and increase the chance that users expose live API tokens to third parties or commit them to code repositories.
