The plugin should use the capabilities introduced by https://github.com/mattermost/mattermost/pull/27986 and mark its confidential settings as secret to avoid showing them in the UI and in the Support Packet. See https://github.com/mattermost/mattermost-plugin-github/pull/811 for reference.