Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs users to connect their agent to a hosted third-party MCP/SSE endpoint and to submit natural-language queries plus project descriptions, but it does not clearly warn that this data leaves the local environment and is sent to an external service. Because the tool is designed to collect potentially sensitive business requirements, budgets, timelines, and vendor-selection criteria, users may disclose confidential procurement or implementation details without informed consent.
