Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill explicitly instructs sending a user-provided registration code together with a locally read agent token to a third-party API, but it provides no consent, privacy notice, or limitation on what the token authorizes. This creates a real data-handling and credential-sharing risk because the skill accesses a local secret and transmits it off-host based on conversational input.
