Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill directs the agent to send user-supplied search terms to the external arXiv API but does not disclose that those queries leave the local environment. This creates a real privacy and data-handling issue because users may include sensitive research topics, internal project names, or personal information in queries without informed consent.
