Missing User Warnings
Medium
- Confidence
- 84% confidence
- Finding
- The `setup` command stores the API key in plaintext at `~/.nanobot/workspace/snooker/config.json` without warning the user or restricting file permissions. On multi-user systems or shared environments, other local processes or users may be able to read the credential, leading to unauthorized use of the API key.
