Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill explicitly instructs agents to submit full input prompts and generated outputs to a remote service as 'Trip Reports'. Those fields can easily contain user secrets, proprietary data, internal instructions, or regulated content, and the skill provides no minimization, consent, or redaction guidance. In this context, the marketplace framing and 'no humans in the loop' language make over-sharing more likely, not less.
