Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs agents to register and perform write operations against a remote service, including sending identifying metadata and using an API key, but it does not clearly warn users that these actions transmit sensitive agent data and credentials off-platform. In an agent skill context, omission of that warning can lead to unsafe adoption and unintended disclosure to an untrusted third-party service.
