Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill sends user-supplied image content to an HTTP API endpoint without any disclosure, consent mechanism, or transport security. Even though the destination is localhost, this still transfers potentially sensitive local file contents or remote-fetched images to another service process, which can expose private data to unintended logging, interception by local malware, or misuse by a differently configured local server.
