Missing User Warnings
Medium
- Confidence
- 86% confidence
- Finding
- The `config set` flow allows storing an API key persistently without any warning, guidance, or visible safeguards about how and where the secret will be stored. In a local CLI that handles a paid or sensitive API credential, this increases the chance users place secrets into plaintext or weakly protected config files, leading to credential exposure through local compromise, backups, logs, or accidental sharing.
