Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The primary setup example embeds `backend.auth.raw` and `message.send.backend.auth.raw` directly in the main configuration sample, which normalizes storing email passwords in plaintext in `~/.config/himalaya/config.toml`. Users often copy primary examples verbatim, so this can lead to credential exposure through weak file permissions, backups, screenshots, dotfile sync, or accidental source-control commits.
