Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill embeds explicit test credentials and an admin token directly in documentation, and although the section is framed as local Vaultwarden testing, it does not prominently warn against reuse outside an isolated local environment. Hardcoded credentials are routinely copied into real setups, committed elsewhere, or left unchanged, which can lead to unauthorized access if the environment is exposed or if users mistakenly treat them as acceptable defaults.
