Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly instructs the agent to send direct proxy requests to the external Cube.js API, but it does not require explicit user confirmation or warn that data may be transmitted off-platform. In an agent setting, this can lead to unintended disclosure of sensitive prompts, query contents, or business data to an external service.
