Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill explicitly instructs the agent to collect and embed images from local paths or remote URLs, but provides no warning, consent step, or restrictions around external resource loading. This can cause clients rendering the Markdown to make unintended network requests, leaking reader IP/user-agent or exposing local file references if the environment resolves local paths automatically.
