Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill encourages converting arbitrary URLs to PDF without warning that this action will initiate outbound network requests and render remote content in a browser engine. This can surprise users, expose IP/network metadata to third parties, and cause the agent environment to fetch untrusted or internal resources if the URL is attacker-controlled.
