Missing User Warnings
Medium
- Confidence
- 84% confidence
- Finding
- This code sends billing-related identifiers and the API key to an external payment service without any visible consent, disclosure, or minimization controls in the skill code. Even though the endpoint uses HTTPS, the function can trigger charges and transmit user-linked payment metadata, which is sensitive behavior in an agent skill context and increases risk of undisclosed billing or privacy violations.
