Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The README explicitly instructs users to place API credentials in predictable local filesystem paths and even shows writing a key via shell redirection. While this is not an exploit by itself, it normalizes insecure secret handling, increases the chance of accidental exposure through backups, logs, screenshots, or permissive file permissions, and provides no warning about protecting those credentials.
