Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs users to connect a hosted MCP server and route searches, fetches, and other live-data requests through a third-party endpoint, but it does not clearly warn that prompts, tool arguments, queries, and retrieved content may be transmitted to and processed by that external service. This creates a real data exposure risk because agents may send sensitive research topics, proprietary URLs, internal identifiers, or other confidential context to the provider without the user making an informed trust decision.
