Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The skill encourages arbitrary proxy requests to an external API without explicitly warning that user-supplied data may be transmitted to Serpdog via Membrane. In an agent setting, this can lead to unintended disclosure of sensitive prompts, identifiers, or business data if the model constructs proxy calls from user content without clear confirmation or scoping.
