Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The setup documentation instructs users to place a bearer token directly into a JSON configuration example but does not warn that the token is a secret, should not be hardcoded, and should be stored using secure secret-management mechanisms. This can lead to accidental credential exposure through source control, screenshots, shared config files, or local compromise, especially because the file is operational setup guidance.
