Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The document tells users to persist `STAYINGAPI_KEY` across future sessions and suggests shell profiles or runtime-managed config without warning that this is a sensitive bearer credential. Storing API keys in broadly loaded startup files or shared config can increase accidental disclosure risk through backups, dotfile sync, shell history mistakes, multi-user systems, or other processes that inherit the environment.
