Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The document explicitly instructs the user to persist `STAYINGAPI_KEY` so it survives across sessions, but it does not warn that shell profiles, plaintext env files, or agent-managed config may store credentials on disk where other users, processes, logs, backups, or future prompts could access them. In an agent-skill context, encouraging durable storage without secure-handling guidance increases the chance of secret leakage beyond the immediate task.
