Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill encourages users to submit arbitrary URLs and supports full-site crawling, but it does not clearly disclose that those URLs and discovered page data are transmitted to the external UXLens service for processing. This can cause unintended data exposure, especially if an agent is pointed at staging, intranet-accessible, authenticated, or otherwise sensitive sites under the assumption the audit is local-only.
