Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill includes concrete instructions for exporting and storing multiple API keys in shell environment variables, but it does not warn about secret exposure through shell history, process inspection, logs, screenshots, or accidental inclusion in scripts and shared terminals. In this operational context, users are likely to copy-paste these commands during incident recovery, which increases the chance of credential leakage and subsequent unauthorized API usage.
