Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill repeatedly instructs agents to call third-party endpoints and to place user-controlled values such as text, theme names, and color parameters into those requests, but it does not warn that this transmits user/context data to an external service. In an agent setting, even seemingly harmless values can contain sensitive project, prompt, or user-derived data, so the omission creates a real data exfiltration/privacy risk.
