Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill instructs users to create runnable integration code that immediately connects to an external MCP endpoint using bearer-token credentials, but it does not clearly warn that executing the templates will transmit authenticated requests off-host. In a skill context that scaffolds code for direct execution, omitting that warning can cause users to unknowingly send prompts and credentials to a third-party service.
