Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill explicitly instructs users to send prompts and contextual inputs to a third-party API, but it does not clearly warn that user-provided content will leave the local environment or describe any privacy implications. In an agent skill context, this omission is security-relevant because users may provide sensitive drafts, proprietary analysis, or internal business information without informed consent.
