Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill requires an API key and directs the user to connect to an external MCP server, which strongly implies that supplied arms, rewards, and contextual/history data may be transmitted to a third-party service. The documentation does not clearly disclose this data flow, retention, or privacy implications, creating a meaningful risk of unintended external sharing of potentially sensitive experimentation or user-behavior data.
