Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill explicitly instructs users to persist authenticated browser state to a local session.json file, but it does not warn that this file may contain reusable cookies, tokens, and other session artifacts. In a browser automation skill, that omission is meaningful because copied, reused, or leaked storage state can enable account takeover or unauthorized session reuse.
