Missing User Warnings
Medium
- Confidence
- 86% confidence
- Finding
- The code performs browser-driven scraping of arbitrary URLs and extracts page body text or YouTube transcript data without any built-in allowlist, consent check, or user-facing notice about what content will be collected. In an agent-skill context, this increases the risk of unauthorized collection of sensitive or copyrighted data and makes misuse easier if the skill is pointed at internal or private resources.
