Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The documentation instructs users to supply an OAuth client secret directly on the command line but does not warn that command-line arguments can be exposed through shell history, process listings, logs, or terminal recordings. In a security-sensitive skill centered on authenticated API access, this omission can lead to credential disclosure and unauthorized use of the Bitquery account or associated data access.
