Missing User Warnings
Low
- Confidence
- 84% confidence
- Finding
- The documentation tells users to place `BAIDU_API_KEY` into environment variables or a local config file but never explicitly states that this key is a secret credential that must not be shared, committed, or exposed in logs. This can lead to accidental credential leakage through source control, screenshots, pasted configs, or shell history, which could allow unauthorized API use and billing abuse.
