Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- This skill explicitly guides the agent/user to expose a local HTTP service to the public internet, but it does not include clear warnings about sensitive data exposure, authentication, access control, or the risks of tunneling development servers. That omission is dangerous because local apps commonly run with debug settings, weak defaults, or access to private files and internal APIs, so publishing them can unintentionally disclose data or enable remote abuse.
