Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly documents saving and loading browser auth state but provides no warning that these files can contain sensitive cookies, tokens, and local/session storage data. In an agent context, this increases the chance that operators persist reusable authenticated sessions to insecure locations or accidentally reuse them across tasks, enabling account takeover or unintended privilege transfer if the state files are exposed.
