Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The example script writes the private key to disk in unencrypted PKCS8 form under the user's home directory, which leaves a long-lived authentication secret exposed to local compromise, backup leakage, or accidental sharing. In an identity system where the private key is the agent's persistent identity, theft enables impersonation, message forgery, and reputation hijacking.
