Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill enables outbound requests to arbitrary user-specified URLs but does not warn users or downstream agents that invoking it can contact external systems. This can lead to SSRF-like access attempts, unintended disclosure of IP/network metadata, or fetching sensitive internal endpoints if the runtime has broader network reach than the user expects.
