Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The README explicitly instructs users to proxy tool calls to arbitrary indexed MCP servers via Nemo, but it does not warn that the supplied arguments and endpoint selection cause data to be transmitted to third-party infrastructure. In an agent-skill context, this is dangerous because users may pass sensitive prompts, tokens, files, or operational data to untrusted remote servers without understanding the trust boundary.
