Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- For URLs classified as public, the code automatically sends the target URL to external cleaning services (r.jina.ai, markdown.new, defuddle.md) before attempting a direct fetch. This can disclose user-requested URLs, embedded path/query data that classification misses, and browsing targets to third parties without explicit consent, which is a real privacy and data-handling risk in a fetch skill.
