Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill instructs users to import Spotify authentication cookies directly from a browser profile, which involves handling active session tokens. Even if intended for legitimate login convenience, this exposes highly sensitive session data without any warning about token sensitivity, scope, storage, or the risk of credential/session compromise if the tool or environment is untrusted.
