Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly instructs users to generate and persist `cookies.json` containing active Xiaohongshu login state in the working directory, but it does not warn that these cookies are sensitive credentials that can enable account takeover if copied. Because the workflow also requires long-lived reuse of those cookies by a local MCP service, the exposure window is extended and accidental leakage through backups, shared folders, or other tools becomes more likely.
