Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The guide explicitly tells users to persist an API key across future sessions, including via shell profiles or runtime-managed config, but does not warn about risks such as plaintext storage, accidental disclosure through dotfile sync/backups, overly broad file permissions, or reuse in shared environments. While this is common operational guidance, omitting secure-storage recommendations increases the chance of credential exposure and unauthorized API use.
