Missing User Warnings
Medium
- Confidence
- 82% confidence
- Finding
- The skill explicitly documents proxying direct requests to the Amplitude API but does not instruct the agent to warn the user that data will be transmitted to an external service or that requests may read or modify production analytics data. In an analytics context, this can expose sensitive user/event data or cause unintended writes if the agent uses the proxy path without clear user awareness.
