Missing User Warnings
Medium
- Confidence
- 86% confidence
- Finding
- The skill provides concrete examples for form filling and content extraction against third-party sites but does not warn that prompts, form fields, page contents, cookies, and other user-supplied data may be transmitted to external domains. In an agent setting, this omission can lead users to automate actions with sensitive data under the assumption the skill is locally safe, creating privacy, compliance, and unintended data disclosure risks.
