Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The tool writes the API key in plaintext to config.json without warning the user that a credential is being persisted on disk. On multi-user systems, shared workspaces, backups, or if file permissions are weak, the key can be exposed and abused to consume the account or access associated service functionality.
