Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill instructs users to copy a full authenticated YouTube Music request as cURL and save it to a local file, then derive a persistent auth file from it, without warning that these materials may contain highly sensitive session headers, cookies, or account tokens. In an agent-skill context, this is dangerous because users may unknowingly expose reusable credentials in the skill directory, logs, backups, or source control, enabling unauthorized access to their YouTube/Google account data.
