Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs collection of highly sensitive X session cookies (`auth_token`, `ct0`) and a Resend API key, then stores them in a local config file. Although it mentions chmod 600, it does not give a clear user-facing warning about the risks of handing session tokens to an agent or the consequences of local persistence, including account takeover, mailbox abuse, and exposure through logs, prompts, or other tools.
