Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly recommends using `--insecure` to bypass TLS certificate validation when certificate errors occur, but it does not warn that this disables server identity verification and enables man-in-the-middle interception. In a web-fetching skill that may retrieve arbitrary URLs over untrusted networks or proxies, this materially increases the risk of tampered content, credential exposure, and unsafe downstream use of fetched data.
