Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill forwards raw user-provided input to an external webhook, which is a real data exfiltration boundary because user queries leave the local skill environment and are transmitted to a third party. The code shows no user notice, consent flow, allowlisting, minimization, or validation, so sensitive user-entered content could be disclosed externally without clear expectation.
