Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to send authenticated requests containing a bearer token to a configurable endpoint, but it does not warn that page contents, typed inputs, navigation targets, and other browsing data will be transmitted to that endpoint. Because the endpoint is environment-controlled and examples even use plain HTTP, a user could unknowingly route sensitive browsing activity or credentials to an untrusted or non-TLS service.
