Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The document instructs users to persist an API key across future sessions in shell profiles or agent-managed configuration without giving any guidance on secret-safe storage, file permissions, rotation, or avoiding logs/history exposure. Persisting bearer tokens in broadly readable startup files or runtime configs can lead to credential leakage to other local users, backup systems, debugging tools, or downstream agents/plugins, enabling unauthorized API use.
