Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly recommends copying an existing TDLib state directory to authenticate another namespace, but it does not warn that this state is effectively a live session artifact that can grant access to a personal Telegram account. In a security-sensitive login helper, normalizing session transfer without ownership checks, storage protections, or revocation guidance materially increases the risk of account takeover, unauthorized reuse, and accidental credential leakage.
