Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly instructs users to manually extract `auth_token` and `ct0` cookies from x.com without a clear warning that these are sensitive session credentials equivalent to account access. Even though the skill frames this as a fallback for posting, documenting raw cookie extraction increases the chance of unsafe handling, leakage into logs/chat, or reuse outside the intended encrypted local flow.
