Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The README instructs users to configure a persistent Authorization header containing a bearer token for a remote MCP endpoint, but it does not warn that the secret may be stored in local client configuration and automatically transmitted on future requests. This creates credential exposure risk through config leakage, shell history or shared environments, and overbroad reuse of the token beyond what users may expect.
