Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The document tells users to persist `STAYINGAPI_KEY` across future sessions but does not warn that this is a sensitive secret or limit storage to secure mechanisms. In agent or shared-shell environments, this can lead to long-lived credential exposure through shell profiles, config files, logs, backups, or other users/processes with access to the host.
