Missing User Warnings
Low
- Confidence
- 95% confidence
- Finding
- The skill recommends importing a Google-hosted web font, which causes client browsers to make requests to a third-party domain and may disclose user IP address, user agent, and related metadata without any privacy notice or self-hosting guidance. In a theming/customization skill this is relevant because it directly encourages embedding remote resources into a production UI, though the impact is limited to privacy leakage rather than code execution or account compromise.
