Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to automatically obtain or use a bearer token and immediately connect to a remote backend, but it does not require explicit user consent or clearly disclose that prompts and uploaded files will be transmitted to a third-party service. This creates a real security and privacy risk because sensitive user content may be sent off-platform using either an existing environment credential or a newly minted anonymous token without meaningful notice.
