Missing User Warnings
High
- Confidence
- 98% confidence
- Finding
- The README explicitly tells users they can place `MINDGRAPH_BASE_URL`, `MINDGRAPH_ACCOUNT`, and `MINDGRAPH_TOKEN` directly into the chat as a fallback configuration method. Even though it says the model should avoid echoing the token, chat input is still exposed to the LLM, may be logged by the host product, retained in transcripts, or surfaced in debugging/telemetry, making credential disclosure a realistic risk.
