Intent-Code Divergence
High
- Confidence
- 99% confidence
- Finding
- The document instructs operators to embed a GitHub token directly in the remote URL, which stores a reusable secret in `.git/config` in plaintext. That contradicts the stated no-cleartext-secrets rule and creates a high risk of credential exposure through local file access, backups, accidental disclosure, or downstream tooling that prints remotes.
