Missing User Warnings
Low
- Confidence
- 83% confidence
- Finding
- The setup instructions tell users to place a long-lived API key in a plaintext local settings file without any warning about local credential exposure, file permissions, or safer secret-handling options. If the workstation is shared, backed up insecurely, or the config file is accidentally committed or exposed, the API key could be stolen and abused for unauthorized API usage.
