Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to send a search query and retrieve external prompt content from SupaSkills, but it does not clearly warn that user task content may be transmitted to a third-party service. This creates a privacy and data-governance risk, especially for sensitive legal, financial, compliance, or security-related requests where users may disclose confidential information.
