Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill documents request fields such as cookies, headers, webhook URLs, and target URLs that are sent to XCrawl, but it does not clearly warn that this data is transmitted to an external third-party service. This can cause users to unknowingly send sensitive session material or internal URLs off-platform, increasing privacy, credential, and SSRF-style exposure risks.
