Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to make external scraping requests using a bearer token from an environment variable, but it does not require user awareness or consent before transmitting prompts/URLs to a third-party service. In an agent-skill context, silent network access plus credential use is a real security and privacy risk because user queries and operational metadata may be sent off-host unexpectedly.
