Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill description advertises semantic search, web scraping, and content extraction, but it does not warn that user prompts, URLs, and retrieved content may be transmitted to third-party Exa infrastructure and other external sites. In agent settings, this can lead to unintended disclosure of sensitive research targets or user-provided data because operators are not given enough information to make an informed consent decision.
