Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill instructs the agent to automatically contact an external backend, generate a client identifier, obtain an anonymous token, and create a session on first open without a clear prior user notice or consent step. This is dangerous because it initiates network activity and account/session creation automatically, potentially transmitting metadata and preparing a remote processing context before the user has affirmatively chosen to connect or upload content.
