Description-Behavior Mismatch
Medium
- Confidence
- 89% confidence
- Finding
- This utility does more than simple token generation: it can create users and automatically select an existing user from the Clerk instance, which expands its capability into account provisioning and user enumeration. In a testing helper this may be intentional, but if run against a non-test Clerk environment it can create unauthorized sessions for arbitrary users and blur the boundary between test tooling and privileged admin automation.
