Local storage is convenient, not a secure vault

Anything in browser storage is readable by any script running on that page.

Which means a single cross-site scripting flaw hands over whatever you kept there, including tokens. It has no protection equivalent to cookie flags that keep values away from scripts. It is a convenient place for preferences and a poor place for anything that grants access.

More on Browser security