Missing User Warnings
Medium
- Confidence
- 86% confidence
- Finding
- The README directs users to add an API token and later states tokens are stored in local files, but it does not warn that these are sensitive credentials or recommend restrictive file permissions. Storing tokens in predictable paths without guidance on chmod/secure storage increases the chance of accidental disclosure through shared accounts, backups, or permissive filesystem settings.
