Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly instructs users to send natural-language queries and an API key to a third-party remote service, but it does not clearly warn that prompts, query contents, and authentication material are being transmitted off-platform. This creates a real privacy and data-governance risk, especially if users submit sensitive business, wallet, or market-intelligence data under the assumption processing is local.
