Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The skill explicitly documents injecting cookies via browser-side script as a way to bypass QR-code login, which normalizes handling session credentials and avoiding the intended authentication flow. In a publishing automation skill, this is unnecessary for core functionality and increases risk of account takeover, session theft, or unauthorized posting if copied or reused.
