Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill advertises web search, crawling, code-context retrieval, and research features backed by an external MCP endpoint, but it does not disclose that user prompts, search terms, URLs, or retrieved context may be transmitted to a third-party service. This creates a real data-exposure risk because users or downstream agents may supply sensitive internal queries or documents under the assumption the skill is local or self-contained.
