Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The code silently persists refreshed session cookies back to a local .env file, which expands the tool from read-only scraping into credential management. Storing live session material on disk increases the chance of credential leakage through source control, backups, logs, or other local compromise, especially because this happens automatically without explicit user approval.
