Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly instructs the agent to send direct proxy requests to an external API without any warning about potential transmission of user, conversation, or system data off-platform. In an agent setting, this can lead to unintended exfiltration of sensitive data if the model constructs requests from ambient context or user-provided content without clear confirmation and data-minimization safeguards.
