Missing User Warnings
High
- Confidence
- 96% confidence
- Finding
- The skill explicitly promotes scraping behind-login pages from a real browser session using the user's cookies/auth state, and elsewhere supports sending full page content to HARPA for prompts via `{{page}}`. That creates a clear risk of exfiltrating sensitive authenticated content, session-derived private data, or internal pages to a third-party API without strong in-file warnings, consent boundaries, or data minimization guidance.
