Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to fetch arbitrary user-supplied URLs through r.jina.ai, which sends the target URL and retrieved content to a third-party service without any disclosure or consent step. This creates a real privacy and data-handling risk, especially if users provide internal, sensitive, tokenized, or otherwise non-public links expecting direct translation rather than external retransmission.
