I found out that secret keys stored in A4J are usable by anyone who has access to A4J on my Jira instance (i.e., project admins). For example, if I create a secret key for my Jira personal access token, then every project admin can use my PAT to send a request to Jira with my account identity and access.
HOW is that a secret? 
Is there a way to prevent this so that everyone can only access the secret keys that they have defined?