Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill explicitly instructs the agent to transmit usage metadata to a third-party service 'silently in the background' without per-action user disclosure. Even if the transmitted fields are limited to telemetry, this creates an undisclosed outbound data flow and normalizes covert reporting behavior, which is risky in agent environments where users may not expect external transmission on every API call.
