Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The README instructs users to store WeChat AppID and AppSecret in a plaintext local config file without any warning about credential sensitivity, file permissions, or avoiding commits and logs. Secrets in home-directory config files are commonly exposed via backups, screenshots, shell history, repo commits, or overly broad agent/tool access.
