Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The README instructs users to paste an account secret token directly into a shell command but provides no guidance on secure handling, storage, rotation, or least-privilege use. In CLI contexts, secrets entered on the command line can be exposed through shell history, process listings, logs, screenshots, or shared terminals, which makes credential leakage a realistic risk.
