Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly instructs operators to pass a raw browser cookie header into an environment variable for authentication, but provides no warning that this value is a highly sensitive session secret equivalent to account access. In an agent or automation context, such cookies can be exposed through logs, shell history, process inspection, screenshots, crash reports, or downstream tool traces, enabling unauthorized publication and account takeover of the Toutiao session.
