Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill instructs users to register an account and send profile data and authenticated requests to an external service without clearly warning that the data leaves the local environment and is processed by a third party. In an agent-skill context, this is risky because users may paste real identifiers or tokens into commands without understanding the privacy, retention, and trust implications.
