Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill is explicitly designed to connect to arbitrary external REST/GraphQL APIs, send requests, and expose logs, but it does not describe any safeguards around data classification, credential redaction, destination allowlisting, or user-consent boundaries. In an agent context, this can enable sensitive prompts, user data, API tokens, or internal metadata to be transmitted to untrusted endpoints or revealed through logs.
