Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill instructs users to connect to an external MCP server over HTTPS but never discloses that search queries, book lookups, and related prompts will be transmitted to a third-party service. This creates a real privacy and data-governance risk because agents may send sensitive user inputs or internal context off-platform without informed consent.
