Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill directs users to send bearer-authenticated requests and Twitter query data to a third-party API but does not clearly warn that prompts, usernames, and access tokens are being transmitted off-platform. This creates a real privacy and security risk because users may submit sensitive investigative queries or misunderstand the trust boundary around the external service.
