Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The setup instructs users to append Amazon access and secret keys into a plain-text ~/.env file without any warning about file permissions, secret managers, or shell-history exposure. This increases the chance that long-lived API credentials are disclosed through local compromise, backups, dotfile syncing, or accidental sharing.
