Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs users to publish agent metadata to a third-party service and frames discoverability as a benefit, but gives no privacy notice, trust boundary explanation, retention details, or warning that this may expose capabilities, endpoints, or identifying information. In a security-sensitive agent ecosystem, encouraging external registration without informed consent can leak operational metadata and increase targeting risk.
