Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The script instructs users to pass the application secret on the command line, which can expose credentials through shell history, process listings, audit logs, or CI job metadata. Although the script is not overtly malicious, this handling pattern unnecessarily increases the chance of credential disclosure.
