Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The CLI stores the user's Bring email/password in config.json and bearer/refresh tokens in token.json under the user's home directory in plaintext. For a shopping-list skill, persistent local storage of reusable credentials and session tokens materially increases exposure to credential theft from local compromise, backups, logs, or other processes reading those files.
