Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The webhook documentation instructs users to send task lifecycle events to an arbitrary external URL but does not warn that task metadata or outputs may be transmitted off-platform. In a skill that can handle user prompts, files, and agent execution results, this omission can lead to unintended disclosure of sensitive data to third-party endpoints.
