Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The README instructs users to place a live API key directly into an environment variable and persist it in shell startup files without any warning about credential sensitivity, shell history exposure, or safer secret-handling methods. This can lead to accidental credential disclosure through shared dotfiles, screen sharing, backups, logs, or multi-user systems, even though the key is not immediately exfiltrated by the skill itself.
