Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The guide explicitly tells users to persist the `STAYINGAPI_KEY` across future sessions but does not provide any cautions about secure secret storage, least-privilege handling, file permissions, or avoiding exposure in shared shell profiles and checked-in config files. This can lead to credential leakage through dotfiles, agent runtime configs, backups, logs, or multi-user systems, especially because the same key grants access to the API across multiple interfaces.
