Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The documentation instructs users to provide sensitive credentials including Twitter authentication cookies and Telegram bot credentials, but gives no warning about secure storage, least-privilege handling, or the risk of account compromise if these values are leaked. In a skill that monitors accounts and sends messages over the network, exposed tokens could allow unauthorized access to social-media sessions or bot operations.
