Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The README instructs users to persist an API key in ~/.bashrc, which can increase the chance of credential exposure through shell history, dotfile backups, shared accounts, or accidental publication of startup files. While this is common operational guidance rather than an exploit, documenting secret persistence without any warning or safer alternatives creates avoidable credential-handling risk.
