Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly instructs use of bearer headers and later demonstrates filling login credentials into a browser session hosted on another machine, but it does not warn that secrets may be exposed to the remote host, browser session, logs, shell history, or any operator of that remote environment. In this context, the omission is security-relevant because the whole purpose of the skill is to drive a browser on a different host, so users may incorrectly assume credentials remain local.
