Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The README instructs users to supply an external HTTP API URL for database schema retrieval but does not warn that schema metadata will be transmitted over the network to that endpoint. Database schema details can reveal sensitive internal structure, and encouraging arbitrary endpoint use increases the risk of unintended data disclosure or SSRF-style misuse depending on how the skill fetches the URL.
