Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The script prompts for an API key and writes it to ~/.satgate/config.json, but it does not clearly warn the user beforehand that the secret will be stored on disk in plaintext. This can lead to unintended credential persistence on shared systems, backed-up home directories, or developer machines where users assumed the value was only used transiently.
