Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill explicitly instructs agents to use a third-party scraping endpoint to fetch arbitrary external URLs, but it does not disclose that both the requested URL and the retrieved content are transmitted through SkillBoss infrastructure. This creates a real privacy and data-handling risk, especially if an agent uses the scraper on sensitive internal, user-specific, or confidential URLs.
