Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill tells users to create and populate a .env file with API credentials but provides no warning that the file contains secrets or guidance on preventing accidental exposure. In a workflow that clones repositories, edits config, and may run API servers, this increases the risk of credential leakage through version control, logs, shared workspaces, or permissive file handling.
