Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill instructs users to store authenticated session cookies in a local file without any guidance on secure storage, least privilege, expiration, or the risk of account takeover if the file is exposed. Session cookies are bearer credentials; anyone who obtains them may be able to impersonate the user on LetPub until the session expires or is revoked.
