Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly documents saving and loading browser auth state, which commonly includes session cookies and local storage tokens, but provides no warning about their sensitivity or safe handling. In an agent context, this increases the chance that credentials are written to disk, reused across tasks, or exposed to other users/processes, enabling account takeover if the saved state is leaked.
