Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill advertises sending messages and tasks to remote agents and supporting API keys/Bearer tokens, yet it provides no warning that user content may leave the local environment and be processed by third parties. In an agent ecosystem, this is especially risky because prompts, task data, secrets, or sensitive outputs could be forwarded to untrusted remote endpoints with little user awareness.
