Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill advertises a live external HTTP endpoint and micropayment-based access but does not clearly warn users that using it may trigger network requests to a third-party service and incur charges. In an agent setting, this can lead to unexpected outbound data sharing, unreviewed interaction with an untrusted endpoint, and unintended paid transactions if the agent or user follows the documented usage blindly.
