Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to open hidden tabs and query external coupon/search sites using merchant and checkout-derived context without clearly disclosing that this browsing sends user-contextual data off-site. Even if only the store name/domain is transmitted, that still reveals where the user is shopping and can create privacy leakage, profiling, and unexpected third-party requests from a checkout session.
