Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill instructs the agent to send authenticated requests to a third-party API using the user's API key, but it does not clearly warn that user-supplied video identifiers, channel URLs, persona, goals, and related query data will be transmitted off-platform to WorthClip's backend. In an agent context, lack of explicit disclosure can cause unintended external sharing of user data and preferences, especially because the skill supports persona/goals endpoints that may contain sensitive profiling information.
