Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The document explicitly instructs the user or agent to persist `STAYINGAPI_KEY` so it survives across sessions, but it does not warn that this may store a live secret in shell profiles, env files, or agent-managed configuration on disk. Persistent credential storage increases the chance of accidental disclosure through dotfile syncing, logs, backups, shared hosts, or later agent access beyond the original task scope.
