Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly recommends `twitterapi-io auth --api-key YOUR_KEY`, which can expose the credential through shell history, process listings, terminal logging, and agent/tool telemetry. Although it also mentions an environment variable alternative, presenting the command-line secret form as a normal authentication path without warning makes accidental credential disclosure reasonably likely.
