Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The README instructs users to extract a live JWT from browser DevTools cookies and pass it on the command line, but provides no warning about the sensitivity of that credential or safer handling guidance. JWTs and shell arguments can be exposed through shell history, process listings, terminal scrollback, screenshots, or logs, which could let an attacker reuse the token to impersonate the user or mint agent tokens.
