Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly recommends sending cross-origin image fetches through a third-party CORS proxy (`https://proxy.corsfix.com/?`) to make DOM capture work, but it does not warn that proxied resources and related request metadata are disclosed to that external service. In the context of capturing DOM content, this can expose sensitive page assets, internal URLs, tokens in query strings, or user-specific content to an untrusted intermediary, making the omission a real privacy and security issue.
