Missing User Warnings
Medium
- Confidence
- 86% confidence
- Finding
- The script sends user queries and the Tavily API key to an external third-party service without any explicit runtime notice, confirmation, or privacy guardrails. In an agent-skill context, users may assume local processing, so sensitive prompts or internal research terms could be unintentionally disclosed to an outside provider.
