Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill instructs users to POST arbitrary markdown to an external AutEng endpoint but does not clearly warn that the full document content will be transmitted off-platform to a third-party service. This creates a real risk of unintended disclosure of sensitive or proprietary data because users may paste internal documentation, credentials, architecture details, or other confidential content into the request without informed consent.
