Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill clearly instructs users to send prompts and other message content to Brave's remote `/chat/completions` endpoint, but it does not prominently warn that user inputs will leave the local environment and be processed by a third party. In an agent setting, this can lead to unintentional transmission of sensitive user data, credentials, internal documents, or regulated information.
