Missing User Warnings
Medium
- Confidence
- 84% confidence
- Finding
- The skill sends user-provided search queries and an API credential to a third-party external service without any in-code disclosure, consent mechanism, or data-handling notice. In an agent setting, users may reasonably assume searches are local or platform-native, so undisclosed transmission can create privacy and compliance risk, especially if prompts contain sensitive data.
