Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The guide explicitly tells users to persist `STAYINGAPI_KEY` across future sessions in shell profiles or agent-managed config without warning that these locations may be readable by other users, exposed in backups, inherited by subprocesses, or accidentally committed. Because this is an authentication secret for a live API, insecure persistence increases the chance of credential leakage and unauthorized API usage.
