Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly recommends saving and loading browser authentication state (`state save auth.json` / `state load auth.json`) but does not warn that these files can contain session cookies and storage tokens that may grant account access if exfiltrated. In an agent-oriented automation context, users may persist auth artifacts to disk or share workspaces, increasing the chance of credential leakage or reuse across sessions.
