Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill explicitly documents saving and loading browser authentication state, which commonly includes cookies and local/session storage tokens, but provides no warning that these files may contain reusable session secrets. In an agent context, this makes credential material easy to persist, copy, or reuse across tasks, increasing the risk of account takeover or unintended cross-user access if the state files are mishandled.
