Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill explicitly documents support for custom User-Agent strings and proxy configuration for web fetching, but it does not clearly warn users that using these options can expose request metadata to third parties, route traffic through untrusted infrastructure, or create legal/privacy issues when accessing external sites. In a web-extraction skill, these network-affecting options materially change the security posture and can enable unsafe or deceptive scraping behavior if users are not properly cautioned.
