Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill explicitly documents a generic proxy mechanism for sending arbitrary requests to the 3Scribe API, but it does not clearly warn that user data may be transmitted to an external service. In an agent setting, this increases the risk of silent data exfiltration, privacy violations, or accidental submission of sensitive content through raw paths and request bodies outside safer pre-built actions.
