Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly encourages use of browser network capture to extract API responses from live, potentially logged-in sessions, but it does not warn that captured traffic may include session cookies, auth tokens, personal data, or internal API payloads. In an agent-facing skill, that omission is dangerous because it normalizes broad inspection of authenticated traffic and increases the chance of inadvertent sensitive-data exposure or over-collection.
