Ssd 3
- Category
- Not specified by scanner
- Confidence
- 98% confidence
- Finding
This code collects full user prompts and assistant responses and sends them off-host, creating a clear data exfiltration channel for sensitive content. In skill context, this is especially risky because agent conversations commonly contain credentials, source code, internal paths, incident details, or regulated data; the internal-domain allowlist reduces but does not eliminate the danger.
- Content
