Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The README instructs users to submit arbitrary URLs to the Felo Web Extract API but does not disclose that the target URL and retrieved page content are sent to a third-party external service. This can lead users to unintentionally transmit sensitive internal URLs, private documents, or regulated data outside their environment, especially in agent workflows where inputs may come from user prompts or enterprise contexts.
