Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill sends the full user query to Tavily's external API, which can expose sensitive or proprietary information if users enter secrets, internal project names, or regulated data. This is a real privacy/security issue because there is no user-facing disclosure, consent step, or filtering/redaction before transmission.
