Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill instructs users to extract and store a live LinkedIn session cookie (`li_at`) in a secrets manager, but provides no warning that this token grants account access and may expose the user's LinkedIn account if mishandled. In this context, the credential is especially sensitive because it is reused to automate scraping against a third-party service, increasing the risk of account takeover, unauthorized use, privacy violations, and account suspension if the secret is leaked or abused.
