Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The documentation explicitly states that API keys, JWTs, and a Solana keypair are persisted to shared config paths and ~/.helius-cli/keypair.json, but it does not warn that these are sensitive credentials whose compromise can enable account takeover, unauthorized API usage, billing abuse, or wallet misuse. In an agent/MCP context where tools may run on shared hosts, developer workstations, or multi-user environments, silent disk persistence materially increases exposure if file permissions, backups, logs, or other local processes are not tightly controlled.
