Missing User Warnings
Medium
- Confidence
- 98% confidence
- Finding
- The skill sends resume files and job description text to an external third-party API, which likely includes sensitive personal and employment data, but it does not explicitly warn the user that candidate data will leave the platform. In an HR context, resumes commonly contain PII and confidential information, so silent transmission materially increases privacy, compliance, and data-handling risk.
