Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The guide shows users passing long-lived access keys directly on the command line and in environment variables, which can expose secrets through shell history, process listings, CI logs, and plaintext files. In the context of an automation/agent skill, this is more dangerous because users are likely to copy these patterns into scripts and unattended workflows, increasing the chance of credential leakage and persistent cloud compromise.
