External Transmission
Medium
- Category
- Data Exfiltration
- Content
## 数据源 - **UUMit API**: `https://api.uumit.com/api/v1/digital-assets` - **ClawHub**: 使用已登录的 `@cx75227-ops` 账户 - 网页前端直接通过UUMit公开API获取实时数据
- Confidence
- 85% confidence
- Finding
- The skill declares that the frontend directly retrieves live data from an external API and also references use of a logged-in account, which creates a real external data transmission and trust boundary. In this context, the skill appears designed to monitor account-linked monetization assets and balances, so sending requests to a third-party service could expose account activity, metadata, or authenticated session context if not tightly scoped and isolated.
