Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The document instructs operators to persist a Google OAuth client secret and user refresh tokens in `~/.canonry/config.yaml` but does not warn that this file becomes a high-value credential store. If local file permissions are weak, backups are shared, or the workstation is compromised, an attacker could recover long-lived secrets and obtain `business.manage` access to managed Business Profiles and associated project integrations.
