Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to fetch arbitrary user-supplied web and WeChat links, including use of a browser path specifically to bypass anti-scraping friction, without any privacy notice or trust boundary explanation. This can cause the system to transmit user-provided URLs and potentially sensitive query tokens to external sites or embedded third parties, creating privacy, tracking, and unintended data-handling risk.
