Context-Inappropriate Capability
Medium
- Confidence
- 99% confidence
- Finding
- The troubleshooting section instructs users to print XFYUN_APP_ID, XFYUN_API_KEY, and XFYUN_API_SECRET directly to the terminal. Secrets echoed in plain text can be exposed through terminal scrollback, screen sharing, shell logging, CI logs, or copied transcripts, leading to credential compromise.
