Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to send user-provided search queries to a remote third-party API but does not disclose that transmission to the user or require consent. This creates a privacy and data-handling risk because users may provide sensitive investment interests or other confidential text that is silently exfiltrated to an external service.
