Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The documentation instructs users to pass a secret token directly on the command line, which can expose the credential through shell history, terminal logging, screenshots, or process inspection on some systems. Even though this is only documentation, it normalizes an unsafe secret-handling pattern that can lead to credential leakage and unauthorized API access.
