Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to send user-supplied URLs to Tavily and retrieve page content, but it does not warn that both the URLs and the fetched content are transmitted to a third-party service. This can expose sensitive internal links, private document locations, or regulated content without informed user consent, especially if users provide non-public URLs.
