Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly instructs the agent to send direct external requests through Membrane's proxy, but it does not require user confirmation or warn that data may be transmitted to an outside service. In an agent setting, this can lead to unintended disclosure of sensitive prompts, contact data, or campaign content to a third-party endpoint without clear user awareness.
