Keeping tokens in plaintext on the client is really common. The alternative would require the user to enter a decryption password on every system start, like some wallets do, which is a bit of a hassle. If at least there was “one obvious way of doing this” across platforms, that’d make things better, but in reality, some tools can’t even put their configs and cache in a sensible location.













yeah, I really don’t get maintainers that try to put human hours to review PRs that are potentially AI generated. This equation will never balance out. There needs to be a first triaging layer that is automated, only then bring a human in the loop if it’s worth continuing.