Intent-Code Divergence
Medium
- Confidence
- 95% confidence
- Finding
- The document claims third-party API credentials are not stored locally, but later instructs users to configure an API key via environment variable. This contradiction can cause operators or agents to handle real secrets locally despite the stated security model, increasing the chance of credential exposure through shell history, process listings, logs, or inherited environment leakage.
