Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill directs users to persist authenticated session material in a temporary cookie jar and then extract an XSRF token from it, but it does not warn that the jar contains live authentication artifacts equivalent to a logged-in parent session. In the context of student records, disclosure of that file to other local users, shell history, backups, or logs could enable unauthorized access to grades, attendance, messages, and documents until the session expires.
