Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill asks users to store Twitter username, password, and email for automated posting/reply actions without clearly explaining the security and privacy risks. If those credentials are mishandled, logged, reused elsewhere, or abused by the automation, an attacker or faulty workflow could take over the account, post unwanted content, or trigger suspension and reputational damage.
