Intent-Code Divergence
Low
- Confidence
- 86% confidence
- Finding
- The documentation recommends `tmap-lbs config set-key <your-key>` as a way to configure the API key. Passing secrets on the command line can expose them through shell history, terminal scrollback, audit logs, and sometimes process listings, which conflicts with the surrounding guidance to avoid revealing the key value. In this skill’s context the risk is limited to local secret exposure rather than direct remote compromise, but it is still an avoidable credential-handling weakness.
