Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The guide explicitly tells users to persist an API key across sessions but does not provide any guidance on secure storage, file permissions, secret-scoping, or the risks of placing credentials in shell startup files or agent-managed config files. This can lead to inadvertent exposure through world-readable dotfiles, backup/sync systems, shell history, debug output, or reuse by unrelated processes running under the same account.
