Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The README embeds an API key-looking value directly in the MCP configuration example without clearly labeling it as a placeholder or warning users not to reuse real secrets in shared config files. Even if this specific value is a demo key, normalizing secret-like strings in documentation can lead users to paste real keys into insecure locations, commit them to source control, or trust exposed credentials.
