Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill encourages direct proxying of arbitrary API requests to a personal finance service without prominent warnings about transmitting sensitive financial data or applying least-privilege constraints. In this context, users may expose account, transaction, budget, or goal data through raw requests that bypass safer, purpose-built actions and increase the risk of over-collection, unintended modification, or privacy leakage.
