Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly instructs the agent to visit a user-provided product site and extract image URLs, which causes external network access and may disclose browsing metadata such as IP address, user agent, timing, and the fact that the agent is interacting with that site. Because this happens as part of the prescribed workflow and without a clear consent or warning step, users may unintentionally trigger outbound requests to third-party domains.
