Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly instructs the agent to send direct proxy requests to an external WP Maps API, but it does not require a user-facing disclosure that data will leave the agent environment and be transmitted to a third-party service. In practice, this can cause sensitive prompts, records, or identifiers to be sent externally without clear user awareness or consent, especially when the proxy path is used as a fallback for unsupported actions.
