Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly documents `vefaas login --accessKey <AK> --secretKey <SK>` but provides no warning that these values are highly sensitive credentials that may be exposed through shell history, logs, screenshots, or copied transcripts. In an AI-agent context, users may paste real secrets into prompts or commands, increasing the chance of credential leakage and subsequent unauthorized access to Volcengine resources.
