Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The documentation tells users to persist a sensitive API token in ~/.bashrc, which increases the chance of long-lived credential exposure through shell history, accidental file sharing, backups, or overly broad local access. While this is common operational guidance, it lacks any warning about secret handling, least privilege, rotation, or safer alternatives, so it constitutes insecure credential-handling advice.
