Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill instructs the agent to send database queries over HTTP to an internal API and then execute a local Python script to process results, but it does not clearly warn about data transmission, sensitivity of returned records, or the side effects of generating documents. In an agent environment, this can lead to unreviewed exfiltration of potentially sensitive data and unsafe execution of downstream processing steps.
