Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The documentation instructs users to auto-extract Zhihu cookies from Chrome and notes elsewhere that the cookie is stored persistently, but it does not clearly warn that session cookies are sensitive authentication credentials equivalent to account access. In a skill that performs authenticated actions, this increases the risk of credential mishandling, accidental disclosure, or insecure local storage practices.
