Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The instructions tell users to store a GitHub token permanently in ~/.zshrc without warning about credential sensitivity, scope minimization, or risks from shell history, local compromise, and accidental disclosure. While not an exploit by itself, it encourages insecure secret-handling practices that can lead to long-lived credential exposure if the machine, dotfiles, or logs are accessed.
