Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill instructs the agent to send a user-supplied URL to the third-party service grabgrab.fun, but the skill description and workflow do not warn the user that their input will be transmitted externally. This creates a privacy and consent issue because URLs may contain sensitive query parameters, private links, or identifying information that the user may not expect to be shared with an outside service.
