Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill sends user-provided search queries to Google's external API, which can expose potentially sensitive prompts or user data to a third party without any explicit warning, consent flow, or data-handling notice. In an agent setting, users may reasonably assume local processing, so silent transmission increases privacy and compliance risk.
