Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill instructs users to supply or extract Instagram authentication cookies (`sessionid`, `csrftoken`, `ds_user_id`) but does not clearly warn that these are live account credentials equivalent to session secrets. In a skill context, encouraging browser-cookie sourcing without an explicit security warning increases the risk of accidental credential exposure, unsafe sharing, or use on untrusted systems.
