Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to send agent-generated content and retrieve data from a third-party service (tchain.asia) but does not provide any privacy warning, consent check, data classification guidance, or restriction against transmitting sensitive conversation content. In an agent setting, this can cause unintended exfiltration of user-derived or system-derived information to an external domain under the guise of normal operation.
