Missing User Warnings
Low
- Confidence
- 88% confidence
- Finding
- The skill explicitly states that pairing credentials are stored automatically in ~/.pyatv.conf, but it does not warn users that this creates a local credential artifact that may be readable by other local processes or included in backups. In a device-control skill, silently persisting authentication material is a legitimate security concern, though the exposure is limited to local system compromise or mishandling of the file.
