Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly sends a required authentication token and user-supplied search keyword to a third-party API, but the manifest provides no user-facing disclosure, consent, or warning about that external transmission. This creates a real privacy and secret-handling risk because users or calling agents may unknowingly expose sensitive tokens or confidential search terms to an external service.
