Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly states that ZenTao credentials are written to a local config file, but it does not warn the user that this file contains sensitive authentication material or advise on securing it. This can lead to accidental credential exposure through weak filesystem permissions, shared accounts, backups, or inclusion in dotfile sync/version control workflows.
