If an API key is exposed on GitHub, attackers can misuse it to make unauthorized requests, leading to unexpected costs, service abuse, or even account suspension by the API provider.
City names can be considered sensitive location data under privacy laws like GDPR. Logging such data may violate user privacy, especially if stored or misused without consent.