Missing User Warnings
High
- Confidence
- 97% confidence
- Finding
- The instructions explicitly extract session cookies, split them into access and refresh JWTs, and use them directly in shell variables and HTTP headers. This exposes highly sensitive authentication material for a financial service and provides no warning about account compromise, token leakage via shell history/process inspection, or safe handling requirements.
