Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill explicitly documents arbitrary proxy requests to the external API without warning that user data, prompts, or supplied parameters may be transmitted to a third-party service. In an agent setting, this can lead to unreviewed outbound data flow and broaden the attack surface if sensitive inputs are passed through raw requests.
