Missing User Warnings
Low
- Confidence
- 83% confidence
- Finding
- The README instructs users to configure an MCP endpoint with an Authorization bearer token and send requests to a third-party hosted service, but it does not clearly warn that both credentials and quote/query contents will be transmitted off-host. This is not inherently malicious, but it can create privacy and secret-handling risks if agents or users assume the skill is local or do not realize prompts, searches, and API keys are being disclosed to an external provider.
