Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The client persists OAuth access and refresh tokens to a local JSON file, which creates credential exposure risk if the host is multi-user, backed up insecurely, or compromised. Although the code sets file mode 0600, it gives no explicit warning or consent prompt before storing highly sensitive brokerage credentials on disk, which is especially important given this skill can place trades through Robinhood.
