Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly instructs the agent to send direct proxy requests to the Terra API but does not warn that request paths, query parameters, headers, and bodies may contain sensitive user or biomedical data that will be transmitted to an external service. In a Terra context, this is more concerning because workspace, dataset, and workflow operations can involve regulated or sensitive research data, so missing disclosure and confirmation increases the risk of unintended data exfiltration or privacy violations.
