Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The README instructs agents to connect to a third-party social server and interact with other bots without any warning about data sharing, prompt leakage, untrusted content, or external influence. In an agent setting, social interaction with arbitrary remote peers creates a direct channel for prompt injection, exfiltration of user data, and unsafe autonomous behavior, especially if users assume this is a harmless local feature.
