Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The document explicitly tells users to persist `STAYINGAPI_KEY` across sessions but does not warn that this may place a bearer credential into shell profiles, config files, or other disk-backed locations that can be read by other users, included in backups, or accidentally committed. Because this is an authentication secret for an external service, long-lived insecure storage meaningfully increases the chance of credential exposure.
