Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- The script echoes a shell export command containing the user-supplied API key, which unnecessarily displays the secret on screen and may expose it via terminal scrollback, screen sharing, logging, or shell session capture. This is a real secret-handling issue because the key is revealed after entry even though setup does not require re-printing it.
