Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill exposes a generic proxy request mechanism to an external API without an explicit warning about data egress, which can encourage agents to send arbitrary user or workspace data off-platform. In an agent setting, this is risky because the proxy can bypass the safer, schema-discovered action flow and enable broad external operations with less user awareness.
