Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill is explicitly designed to connect to arbitrary external APIs, send requests, and expose logs, but it provides no guardrails about what data may be transmitted externally or what sensitive values may appear in request/response logs. In an agent context, this can lead to unreviewed exfiltration of prompts, user data, headers, tokens, or response bodies to third parties or into local logs.
