Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to automatically connect to a remote backend and, if no token is present, silently obtain an anonymous token and create a session on first open. This causes network activity and credential issuance without clear prior user consent, which can surprise users, create privacy concerns, and establish persistent remote state tied to user interaction.
