Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The guide instructs users to configure long-lived Access Key credentials directly in CLI config and shell environment variables without any warning about secret exposure, persistence, shell history, or use of safer alternatives such as short-lived credentials/RAM roles. In a troubleshooting skill for cloud Elasticsearch, operators are likely to run these commands on admin workstations or shared bastions, which increases the chance of credential leakage and subsequent compromise of cloud resources.
