Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs the user to extract HttpOnly authentication cookies from a signed-in browser session and reuse them in shell commands. That effectively converts a protected browser credential into a bearer token available to the shell environment, logs, history, and child processes, increasing session hijack risk if the machine, terminal history, or process environment is exposed.
