Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs users to publish and subscribe to agent identity and status data over an MQTT broker, but it does not warn that these messages may expose operational metadata, identifiers, or activity patterns to other local or network participants. Because MQTT is a network messaging system and the examples encourage sharing agent IDs, roles, and activities, users may unintentionally disclose sensitive information or enable profiling if the broker is shared, misconfigured, or later exposed beyond localhost.
