Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly asks for and uses user credentials for browser-driven interaction, but provides no guidance on minimizing, masking, securely handling, or avoiding persistence of secrets. In an agent workflow that may log prompts, screenshots, browser state, or generated artifacts, this can lead to unnecessary exposure of usernames, passwords, session details, or privileged access paths.
