Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The tool allows caller-supplied HTTP headers to be forwarded to any arbitrary URL, which can disclose sensitive values such as Authorization, Cookie, or internal API keys to untrusted third-party hosts. In an agent setting, this is especially risky because other prompts or tools may induce the agent to reuse confidential headers across domains, turning the scraper into a data-exfiltration primitive.
