Intent-Code Divergence
Medium
- Confidence
- 92% confidence
- Finding
- The guide states that examples use a sandbox with no API key required and that credentials are user-supplied, yet the code later hardcodes an API key and sends bearer-authenticated requests. This inconsistency can mislead operators into trusting the examples and normalizing unsafe credential handling practices, increasing the chance of accidental secret exposure or unauthorized external calls.
