Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The webhook feature sends submitted form data to any configured external HTTPS endpoint, which can disclose sensitive responses to third parties if a workflow owner misconfigures or abuses the destination. In a human-input collection skill, responses may contain approvals, personal data, or uploaded content, so the lack of an explicit privacy warning and destination-validation guidance increases the risk of unintended exfiltration.
