Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to upload code to GitHub Gist, which sends potentially sensitive code or metadata outside the local environment, but it does not require an explicit user-facing warning or confirmation at the point of exfiltration. Even with a sensitive-data scan and secret-gist default, users may not realize their code is being transmitted to a third-party service, creating privacy, confidentiality, and compliance risk.
