Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill explicitly recommends transporting an authentication cookie in the URL query string, which is unsafe because URLs are commonly exposed through browser history, server/access logs, analytics systems, reverse proxies, referrer headers, screenshots, and copied links. In this skill's context, the value is a bearer authentication token that grants access to the agent-facing web session, so leakage can directly enable session hijacking.
