Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs the user to run a sidecar that collects local health and environment data and sends it to a remote service, but it does not present a clear upfront warning about the scope of data exfiltration or obtain informed consent. In a security-sensitive agent environment, health data, logs, integration status, workspace files, and model/auth diagnostics can contain secrets, internal topology, and operational metadata that materially increase risk if transmitted externally.
