Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The documentation explicitly describes where bearer access and refresh tokens are stored in browser cookies and how to extract them, but provides no warning about treating them as secrets or limiting their use. In this skill's context, those tokens grant access to a live Gousto account and can enable account data access and order modification, so exposing handling guidance without security guardrails materially increases the chance of credential misuse or accidental leakage.
