Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The guide explicitly instructs users to persist `STAYINGAPI_KEY` across future sessions but does not mention that the value is a sensitive secret or recommend secure storage mechanisms. In agent/runtime environments, this can lead to credentials being written into shell profiles, plaintext config files, logs, or shared workspaces where other users, tools, or later prompts can access them.
