Missing User Warnings
Medium
- Confidence
- 98% confidence
- Finding
- The guide explicitly prints the private key to stdout and serializes it with NoEncryption(), which can expose the credential through terminal logs, shell history capture, CI logs, screen recording, or shared consoles. In an identity system where the private key is the persistent root of agent identity and signing authority, key disclosure enables impersonation, unauthorized signing, and reputation hijacking until revocation.
