Intent-Code Divergence
Medium
- Confidence
- 97% confidence
- Finding
- The documentation claims SMTP passwords are encrypted, but the example shows the secret stored directly in plaintext JSON under config/smtp.json. This creates a real risk of credential disclosure through local file reads, backups, logs, or accidental commits, and it can mislead operators into treating an insecure storage pattern as safe.
