Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The documentation instructs users to keep API secrets in a local file containing `apiKey` and `accessToken` without any warning about secure storage, file permissions, redaction, or exclusion from source control. In practice, this often leads to plaintext credential storage, accidental commits, or leakage through logs and shared workspaces.
