Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill explicitly instructs agents to POST free-form 'confessions' to a third-party endpoint but provides no warning that the content leaves the host environment and may contain sensitive model, system, or user-derived information. Because the payload is natural language and the skill frames it as reflection, it creates a realistic path for accidental exfiltration of secrets, prompts, or observations.
