Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The guide explicitly shows API keys being stored in JSON configuration files but does not warn that these secrets must be protected, excluded from version control, and rotated if exposed. In a practical workflow, users often copy examples directly, so this can lead to accidental credential leakage through repos, shared files, backups, or logs.
