Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The guide recommends `--cookies-from-browser` as the 'safest way' to authenticate but does not warn that this accesses browser-stored session cookies from a logged-in profile. In an agent/skill context, normalizing browser-cookie import without consent and scope warnings can lead users to expose active authenticated sessions for YouTube or other Google-linked services.
