Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The configuration examples include `backend.auth.raw = "your-password"` and similar SMTP plaintext password storage in the main setup section, which can normalize insecure credential handling. Users may copy the example verbatim into `~/.config/himalaya/config.toml`, exposing mailbox credentials to local compromise, backups, accidental sharing, or source-control leaks.
