Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill directs users to submit task data to an external verifier service, which creates a real data exfiltration boundary. Although the document briefly says not to include secrets or private data, it does not clearly foreground that data is being transmitted to a third-party endpoint, what trust assumptions apply, or what privacy/security guarantees exist, so users may send sensitive task outputs or metadata off-platform.
