Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to send user-supplied URLs and retrieve page contents through a local browser service, but it does not warn that requests and fetched content are transmitted to another component. This can create privacy and trust issues, especially if users do not realize sensitive URLs, tokens in query strings, or internal endpoints may be accessed and processed by that service.
