Missing User Warnings
Medium
- Confidence
- 84% confidence
- Finding
- The README tells users to paste an API key during setup without any guidance on secure credential handling, which can normalize unsafe practices such as exposing secrets in shared terminals, shell history, logs, or screenshots. In an agent/CLI context, this is more dangerous because users may run setup in automated or observed environments where credentials can be captured and reused for full account access.
