Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill is configured to make remote HTTP(S) requests to a user-supplied UPLO instance and exposes capabilities such as search, policy retrieval, directives, and organization context export, but the manifest provides no explicit warning that prompts and potentially sensitive enterprise data may be sent off-platform. In an energy-sector context, this is more sensitive than generic web search because the referenced data may include grid, safety, regulatory, and operational information.
