Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs the agent to persist the user's Agnes API key to ~/.agnes-ai/api_key in plain text and does not warn the user about local secret storage or its risks. Plain-text credential persistence increases exposure to other local users, malware, backups, shell history mistakes, and accidental disclosure through logs or support bundles.
