Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The examples include commands that write secret material to local files and inject secrets into configuration output without any warning about secure file permissions, cleanup, or avoiding persistence. In documentation for a secrets-management CLI, this can lead users to store sensitive values on disk in ways that are later exposed through backups, logs, world-readable files, or source control.
