Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The document explicitly tells users to persist `STAYINGAPI_KEY` across future sessions but does not provide any guidance on secure storage, least-privilege handling, rotation, or avoiding exposure in shared shells and profile files. Long-term credential persistence increases the chance of accidental disclosure through shell history, dotfile syncing, backups, multi-user access, or agent/runtime logs.
