Missing User Warnings
Medium
- Confidence
- 83% confidence
- Finding
- The skill instructs users or agents to upload local files to an external domain without any trust boundary warning, data classification guidance, or consent checkpoint. In an agent context, this can lead to unintended exfiltration of locally available files or proprietary content to a third-party service, especially if the agent generalizes from the examples and selects files automatically.
