Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The README promotes web search, scraping, content extraction, and deep research through an external UnSearch API but does not clearly disclose that user prompts, search queries, and supplied URLs will be transmitted off-host and may trigger network fetches to third-party sites. This can lead users or downstream agents to send sensitive data or internal URLs externally without informed consent, increasing privacy, data exfiltration, and SSRF-like risk in environments where agents can access non-public resources.
