Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The file explicitly documents using the browser bridge to access session-authenticated account endpoints such as `/api/v3/users/me/orders/` with no accompanying warning that this exposes private user data from the currently signed-in Eventbrite account. In an agent skill context, this increases the chance that an automated workflow queries or reveals personal order history without the user's informed consent, especially because it presents the session-auth path as a convenient fallback when no token is configured.
