Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill routes user-supplied IP addresses to a remote MCP endpoint backed by a third-party lookup service, but the description does not clearly warn users that queried IPs will leave the local environment. This creates a privacy and data-handling risk, especially if users submit internal, customer, or otherwise sensitive IP addresses under the assumption the lookup is local or self-contained.
