Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill exposes a generic authenticated proxy request mechanism to the external Kotive API without requiring explicit user confirmation or warning that arbitrary data may be transmitted off-platform. This increases the chance that an agent will send sensitive user or workspace data to third-party endpoints through broad, minimally constrained requests.
