Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The instructions tell users to place a live DeepSeek API key in config.json but provide no warning about secret leakage, file permissions, accidental commits, or safer alternatives. This is dangerous because config files are commonly checked into version control or shared, which can expose the API key and allow unauthorized API use and billing abuse.
