Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The document explicitly tells users to persist `STAYINGAPI_KEY` across future sessions in shell profiles or runtime-managed config without any guidance on secure storage, file permissions, secret managers, or risks of plaintext credential exposure. That can lead to accidental disclosure through dotfile sync, backups, shared systems, process inspection, or repository commits, especially because the key enables access to an external API account.
