Missing User Warnings
Medium
- Confidence
- 86% confidence
- Finding
- The skill explicitly instructs operators to inspect authenticated API traffic and fetch same-origin endpoints from a logged-in browser context. That enables access to private account data, tokens, and backend responses tied to a real user session, yet the documentation provides no privacy, authorization, or data-handling guardrails. In a skill centered on persistent stealth profiles and session reuse, this meaningfully increases the risk of unauthorized data access or collection.
