Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly supports remote image upload by URL/base64/file ID and notes that outputs are stored in cloud storage by default, but it does not prominently warn at the start that user-provided images and derived outputs are transmitted to a third-party service and retained for up to 7 days. This can lead agents or users to send sensitive screenshots, IDs, or private imagery off-platform without informed consent or minimization.
