Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The script writes KEYAPI_TOKEN directly into the user's shell profile or PowerShell profile, which is a plaintext startup file that may be readable by other local users, backup systems, dotfile syncing tools, or accidentally committed to source control. Although this appears intended as a convenience setup flow rather than malicious behavior, persisting bearer tokens in shell init files increases the chance of credential disclosure and long-term token exposure.
