Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly instructs the agent to send externally hosted images directly to the user without mentioning trust checks, content screening, or remote-content/privacy implications. This can expose users to unsafe or NSFW images, tracking via third-party image loads, and delivery of deceptive or malicious visual content from untrusted domains.
