When you go to the debug console and use: walletpassphrase mypassword 1000
and then close the console. You expect that the client wallet will be locked in 1000 seconds.
It is, except that if someone comes along and opens the debug window they can then see your previous command in the history and see the password.
The debug history should be cleared of walletpassphrase entries on exit.