Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The README instructs users to place a long-lived API key in a local config file without any warning about credential sensitivity, file permissions, rotation, or secure storage. If the config file is readable by other local users, synced to cloud storage, committed to a repository, or exposed by malware, the key could be stolen and used to impersonate the user against the dalongxia service.
