Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly promotes creating signed public attestations and using transfers with `visibility: "public"`, and it configures a remote MCP endpoint, but it does not clearly warn users that plugin identifiers, hashes, behavior reports, and handoff context may be transmitted to an external service and potentially made publicly visible. In a security-sensitive agent environment, this can lead to unintended disclosure of operational metadata, provenance data, or sensitive workflow context because users may treat these actions as local trust bookkeeping rather than remote publication.
