Missing User Warnings
High
- Confidence
- 97% confidence
- Finding
- The skill instructs users to export X/Twitter authentication cookies from Chrome and place them next to a downloaded executable, but provides no warning about the sensitivity of those cookies or the risk of account takeover if they are exposed. Because the executable then exposes account functionality through a local API, any local process or malware able to reach that service may be able to act as the user.
