Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly encourages direct proxy requests to external API endpoints but does not warn that arbitrary request paths, headers, query parameters, and bodies may send user-provided or system-derived data off-platform. In an agent setting, this increases the risk of unintended data disclosure, especially if the model constructs proxy calls from ambiguous prompts or includes sensitive context in requests.
