Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill prominently encourages `web_fetch` calls to multiple third-party search engines but does not warn users that their queries, operators, and potentially sensitive research terms will be transmitted to external services. In an agent setting, this can cause unintended disclosure of proprietary, personal, or confidential information, especially because the examples normalize direct outbound requests across many providers.
