Missing User Warnings
Low
- Confidence
- 93% confidence
- Finding
- The skill instructs users to connect to a remote MCP server via `npx mcp-remote@latest https://gateway.pipeworx.io/mathjs/mcp` but does not clearly warn that using the skill sends requests over the network to a third-party service. This can mislead users into treating the tool as local-only and may expose prompts, inputs, or metadata to an external operator, which is a real transparency and privacy risk even though the described functionality is only math evaluation.
