Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The README instructs users to place a long-lived Home Assistant token in persistent shell startup files, which increases the chance of credential exposure through local file disclosure, shell config syncing, backups, shared accounts, or accidental publication. Because this token grants API access to a home automation system, compromise could let an attacker monitor devices or control connected services in the home.
