Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The document instructs users to append a long-lived API token directly into a shell startup file, which persistently exposes the secret to anyone with access to the user profile and can also encourage unsafe handling practices on shared systems. While it is standard operational guidance rather than overtly malicious behavior, the nearby text does not clearly warn about risks such as local file disclosure, backups, dotfile syncing, or multi-user access.
