Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to publish directly to Xiaohongshu using stored login cookies, but it does not require an explicit user confirmation, disclose that an external account action will occur, or warn that account/session data will be used. In an agent setting, this can lead to unintended posting, reputational harm, or misuse of the user's authenticated session if the workflow is triggered automatically or ambiguously.
