Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly documents arbitrary proxy requests to an external API without requiring user confirmation or warning that supplied paths, query parameters, and request bodies may transmit user, tenant, or system-derived data off-platform. In an agent setting, this increases the risk of unintended data exfiltration or privacy violations because a model may compose raw requests from available context rather than using constrained actions.
