Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The documentation shows use of sensitive credentials (`api_key`, `stream_key`) and immediately uses bearer-token authentication, but does not warn against logging, echoing, committing, or exposing those secrets in chat, screenshots, or client-side contexts. In an agent setting, this increases the chance that implementers mishandle long-lived credentials and accidentally leak control of the stream account.
