Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs users to store a newly issued API key in a plaintext file under ~/.config/moltguild/credentials.json, but does not recommend file-permission hardening, OS keychain storage, encryption, or other secret-management controls. On multi-user systems, compromised hosts, backups, logs, or agent tooling that scans home directories, this can expose the API key and allow account impersonation and unauthorized actions on the platform.
