Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The example instructs users to export long-lived cloud access credentials directly into shell environment variables without any accompanying warning about secret handling, shell history, shared terminal sessions, or safer alternatives. While common in setup docs, this can lead to accidental credential exposure through process listings, terminal logging, screenshots, CI logs, or reused shells, especially in infrastructure workflows where the credentials are highly privileged.
