Of course you'll need to include that sensitive data in the script, though the first few characters of AWS credentials should be unique enough.
I thought about setting up something similar for networking. If a packet contains my password in cleartext then pop up a warning allowing/denying (denying would have to force the connect to close, I guess). Might be too much overhead though.