Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The README encourages several credential handling methods, including command-line arguments and plaintext config files, but never warns that these approaches can expose API keys through shell history, process listings, checked-in files, CI logs, or overly permissive file permissions. In a developer-tool skill intended for use across local environments, CI/CD, and shared workspaces, this omission materially increases the chance of accidental secret disclosure.
