Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs users to call a raw HTTP endpoint by IP address, which exposes requests and responses to interception or modification in transit and provides no authenticity guarantees for the remote service. In the context of an agent skill, this is more dangerous because the endpoint may receive user queries or behavioral data, and users are given no warning about transport insecurity or privacy risks.
