Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly documents a generic proxy capability that can send arbitrary requests to the external OCR service, but it does not require user confirmation, scope restrictions, or warnings about transmitting sensitive document contents and metadata. In a document/OCR context, this increases the risk of unintended exfiltration of sensitive files, extracted text, or identifiers to a third-party service through broad agent-directed API access.
