Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The documentation explicitly instructs users to copy a live authenticated session cookie from browser devtools and pass it to a script. A session cookie is a bearer credential equivalent to account access, so encouraging its extraction and transfer materially increases the risk of credential theft, account takeover, and reuse outside the intended browser context.
