Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The document explicitly instructs the user to persist a long-lived API key across sessions and suggests storing it in shell profiles or runtime-managed config without any guidance on secret storage hardening. That increases the chance of credential exposure through dotfile syncing, local compromise, backups, logs, or accidental sharing, especially because the same key grants access across multiple services.
