Missing User Warnings
Medium
- Confidence
- 80% confidence
- Finding
- The skill directs the agent to fetch and analyze user-supplied URLs, which creates network-access and privacy exposure without clearly warning the user or requiring confirmation. This can enable unintended access to internal, sensitive, or user-specific endpoints if the runtime permits arbitrary outbound requests, making it an SSRF-adjacent risk in agent environments.
