Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The README includes example payloads that transmit sensitive authentication material, including an API key and a bearer token, without any warning that secrets must not be shared in plaintext, logs, demos, or inter-agent messages unless properly redacted and protected. In an API gateway setup, this is especially risky because operators may copy these examples into real testing workflows, normalizing unsafe handling of credentials and increasing the chance of credential leakage through terminals, logs, chat, or monitoring systems.
