Missing User Warnings
Medium
- Confidence
- 98% confidence
- Finding
- The workflow explicitly instructs passing raw headers, including Cookie and User-Agent, into a replay script without warning that these may contain session tokens, API keys, or identifying data. Because the skill is designed to replay malicious payloads against targets, it increases the chance of forwarding live credentials to external systems or using them in unauthorized vulnerability verification, which can lead to account compromise or unauthorized access.
