Missing User Warnings
- Category
- Not specified by scanner
- Confidence
- 93% confidence
- Finding
The skill explicitly instructs the agent to make outbound requests to a third-party service, reuse a stable
patron_id, read externally supplied content, and potentially post notes or letters, but it provides no user-facing consent boundary or warning about data disclosure. This creates a real privacy and prompt-injection risk because agent state, identifiers, and user-derived information may be transmitted or influenced by untrusted remote content without explicit approval.- Content
