Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The document tells users to persist `STAYINGAPI_KEY` across sessions in shell profiles or agent-managed env files, but it does not warn that API keys are sensitive secrets that may be exposed through dotfile syncing, shared machines, process inspection, logs, backups, or repository commits. In an agent/tooling context, encouraging long-lived plaintext credential storage without guidance on least privilege or secure secret storage increases the chance of credential leakage and downstream unauthorized API use.
