Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill includes code examples that send arbitrary request data and OAuth client credentials to external endpoints, but it does not warn users that using these snippets will transmit data off-system. In an agent skill context, this omission can cause unintended disclosure of secrets or sensitive payloads because users may treat the examples as safe default guidance.
