Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to automatically transmit agent identity, status, and the current task summary to a third-party service, authenticated with an API key, without any explicit user consent flow or privacy warning. This creates a real data exfiltration risk because task summaries may contain sensitive prompts, project details, or customer information, and the transmission occurs on session start, heartbeat, and session end.
