Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The guide explicitly tells users to persist a live API key so it is available in every future session, but it does not warn about secure storage practices, least privilege, rotation, or the risk of exposing credentials through shell history, shared profiles, dotfiles, logs, or multi-user systems. Because the same key grants access to paid live API usage, insecure persistence can lead to credential theft, unauthorized requests, and billing abuse.
