Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The document instructs users to persist `STAYINGAPI_KEY` across future sessions, including shell profiles or runtime-managed env files, but does not warn that these locations store long-lived credentials on disk and may be readable by other users, processes, backups, or support tooling. Because the key authorizes API access and potentially billable live requests, encouraging persistent storage without minimal handling guidance increases the chance of credential leakage or accidental exposure.
