Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The document explicitly instructs the user to persist `STAYINGAPI_KEY` across sessions in a shell profile or agent-managed config, but it does not warn that these locations may be readable by other local users, inherited by subprocesses, synced to dotfile repos, or exposed in logs and debugging output. Because this is an API credential for a third-party service, normalizing long-lived plaintext storage increases the chance of accidental disclosure and unauthorized API usage.
