Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill prominently instructs users to send email addresses, site domains, categories, page URLs, and API-authenticated requests to a third-party service without any privacy, consent, or data-sharing warning. In an agent setting, this can cause users or upstream systems to disclose operational metadata and credentials to an external network without informed approval.
