Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The script explicitly reads Facebook anti-CSRF/session-related tokens (DTSG, LSD), site metadata, and the current user ID from the page context, then uses them to issue authenticated GraphQL requests on behalf of the logged-in user. Even though the values are not exfiltrated to a third party in this snippet, accessing and operationalizing authentication material without clear user disclosure or consent expands the skill's privilege and enables bulk extraction of group content using the user's session.
