Intent-Code Divergence
Medium
- Confidence
- 86% confidence
- Finding
- The documentation claims credentials are 'default non-persistent' while also promoting persistence to `.env` and encrypted storage, which can mislead users about actual secret-handling behavior. Ambiguous safety claims around credentials increase the chance that sensitive cloud keys are stored locally without fully informed consent.
