A shell that's just on your network isn't good enough to exploit this. The attacker would need a shell on your computer, either running as you or as an administrative user. And given that, your data isn't safe anyway even if it weren't in cleartext.
What I think you're missing is the possibility of using these tokens as an attack vector in this case - social engineering. Impersonating a senior manager or a C level entity.
So while on the surface you can say that the risk is minimal this can be damaging to a business provided you impersonate the "right" person.
I'm not saying it's not a big deal if those tokens get stolen. I'm saying that if your tokens could get stolen this way, they could get stolen a different way even if they weren't stored in cleartext like this.