Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill sends user-supplied travel queries to a hard-coded third-party proxy endpoint along with an embedded token, but provides no user-facing disclosure that destination, itinerary, and related inputs are being transmitted off-platform. This creates a privacy and data-governance risk because users may reveal sensitive travel plans, and the hard-coded remote proxy also expands the trust boundary to infrastructure outside the skill host.
