Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The guide instructs users to persist the `STAYINGAPI_KEY` across future sessions but does not warn that shell profiles, shared env files, or agent-managed config can expose secrets to other local users, child processes, logs, backups, or version-controlled files. Because this is credential-handling documentation for an API key, omission of secure-storage guidance can lead to unintended disclosure and unauthorized use of the account.
