Some people are confused why this could be a big deal. An analogy: on GitHub, if you echo a GitHub access token in an action’s log, it will be automatically censored. This post would be like noticing that someone’s action step is just named ghp_1ae27h… and that the name isn’t censored, and speculating on what that says about the token-censorship algorithm
Key point: if you try it yourself, it will be in clear-text for you (you already know your password, so there's no issue), but everyone else will only see "***".