Missing User Warnings
Low
- Confidence
- 84% confidence
- Finding
- The documentation instructs users to place an API key in a local .env file but provides no guidance on secret handling, storage hygiene, or exclusion from version control. This increases the chance of accidental credential exposure through commits, logs, shared workspaces, or insecure file permissions.
