Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to call an external third-party API but does not clearly disclose to the user that their request context may be sent off-platform. This creates a privacy and consent risk, especially if a user includes sensitive details in a news-related query and the agent forwards them to the Railway-hosted service without explicit notice.
