Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The guide explicitly tells users to persist a long-lived API credential across future sessions and suggests shell profiles or runtime-managed config without warning that these locations may be readable by other users, exposed through backups, logs, dotfile sync, or accidental disclosure. While storing API keys is sometimes necessary, omitting secure-storage guidance increases the chance of credential leakage and unauthorized use of the StayingAPI account.
