External Transmission
Medium
- Category
- Data Exfiltration
- Content
The tools live on a remote MCP endpoint. Add it to your agent, authenticating with your tenant API key (set `AGENT4_API_KEY`; get a key from **console → Settings → Security**, shown once at creation): - **URL:** `https://api.agent4.io/v1/mcp` - **Header:** `X-API-Key: $AGENT4_API_KEY` - **Transport:** streamable-http
- Confidence
- 97% confidence
- Finding
- This skill explicitly instructs the agent to send agent configurations, knowledge-base contents, and queries to a third-party remote service at api.agent4.io using an API key. While this is the intended product behavior, it is still a real data-exfiltration boundary: sensitive user content may leave the local environment and be stored or processed remotely, so misuse or misunderstanding could expose confidential business data.
