Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill instructs users to supply authentication cookies via environment variables or local .env files but does not include an explicit warning that these cookies are highly sensitive session credentials. In an agent context, users may expose reusable login tokens to tooling or logs without understanding the privacy and account-takeover risk if those values are leaked, persisted, or echoed.
