Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill sends user-supplied travel search data, including city and query terms, to a third-party proxy endpoint using a hard-coded token, but there is no disclosure, consent flow, or indication to the user that their inputs are being relayed off-platform. In a travel assistant context, queries can reveal sensitive itinerary, location, and booking intent data, so undisclosed transmission to an external service creates a real privacy and data-handling risk.
