Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly states that upstream API response bodies are returned as-is, but it does not warn that those responses may contain untrusted external content. In an agent setting, verbatim external content can carry prompt-injection instructions, misleading links, or unsafe text that may be forwarded downstream without scrutiny.
