Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The documentation instructs users to place host, username, and password directly into TOOLS.md, which encourages plaintext secret storage in a likely user-managed file. This increases the risk of credential leakage through source control, backups, logs, screenshots, or accidental sharing, especially because these credentials grant access to surveillance infrastructure.
