Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The documentation instructs users to create a .env containing a client secret and later notes that OAuth tokens are stored on disk, but it provides no explicit warning about protecting these secrets, excluding them from source control, or limiting file permissions. In an agent or shared workstation context, this increases the chance of credential leakage and subsequent unauthorized control of the Homey hub.
