Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly documents using the browser's authenticated Eventbrite session to access `/api/v3/users/me/orders/` and similar endpoints, but it does not warn that this exposes personal account data and organization data from the currently signed-in browser profile. In an agent skill context, this can lead users to unknowingly authorize retrieval of sensitive order, attendee, or account information through a local browser bridge, especially because the same section frames it as convenient when no token is configured.
