Missing User Warnings
High
- Confidence
- 99% confidence
- Finding
- A hardcoded bearer token is embedded directly in the script and then used to authenticate outbound publishing requests. Anyone with access to the file can reuse the credential to publish, modify, or abuse the associated account/API privileges, and secrets committed to source are commonly leaked via repos, logs, or package distribution.
