Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to send user-supplied WeChat article URLs to an external third-party service (`down.mptext.top`) without any disclosure, consent, or privacy warning. Even if the URL is 'just a link,' it may contain private, unlisted, tokenized, or user-specific content, and forwarding it to a third party creates unnecessary data-sharing and tracking risk.
