Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill description emphasizes that it works without an API key but does not clearly disclose that user queries are transmitted to Baidu by scraping live search-result pages. This can mislead users and downstream agents about privacy, compliance, and network egress implications, causing sensitive prompts or internal data to be sent to a third party without informed consent.
