Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill documents that user-supplied URLs, queries, and crawled page content are processed through the third-party SkillBoss API Hub and multiple backend providers, but it does not clearly warn users that this data leaves the local environment. This can lead to unintended disclosure of sensitive URLs, search terms, internal endpoints, or scraped content when users assume the skill operates locally.
