Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The guide tells users to persist `STAYINGAPI_KEY` across future sessions and suggests shell profiles or agent-managed config without warning that API keys are sensitive secrets that can be exposed through dotfiles, backups, process environments, shared machines, or overly broad runtime access. While this is common setup guidance, omitting secret-handling precautions increases the chance of accidental credential disclosure and misuse of the StayingAPI account.
