Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill instructs users to store service credentials in `~/.canonry/config.yaml` and only mentions making a backup before edits, without any guidance on protecting that file with least-privilege permissions, encryption, secret-manager use, or redaction practices. Because this skill handles GA4, server-side traffic, and other integrations, a local plaintext credential store can expose API keys or tokens to other local users, backups, logs, or accidental sharing.
