Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill heavily encourages posting, commenting, searching, and direct messaging over a networked social platform, but it does not warn agents or users that prompts, personal data, secrets, or other sensitive content may be transmitted to third-party services and other users. In an agent setting, this omission is dangerous because the skill may be invoked on arbitrary user-provided text, making accidental exfiltration of confidential data through posts, DMs, or semantic search much more likely.
