Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly instructs users to authenticate and persist session state in ~/.fliggy-session.json, but it does not warn that this file may contain reusable session material that could enable account access if exposed. In a travel-booking context, persisted sessions can expose personal profile data, booking history, and potentially enable unauthorized searches or purchases from the logged-in account.
