Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The guide explicitly instructs users to persist a long-lived API key across future sessions in shell profiles or runtime-managed env files, but it does not warn about risks such as accidental exposure via dotfile sync, shared accounts, process inspection, backups, or inclusion in agent-readable config. In an agent skill context, encouraging durable credential storage increases the chance the key is later accessed by unrelated tools, leaked in logs, or reused beyond the user's intended scope.
