Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs users to upload full contract text and send it to an external endpoint (`https://ai-gaoqian.xyz/review`) but does not clearly warn that potentially sensitive legal documents are transmitted off-platform to a third-party service. Because contracts commonly contain confidential business, personal, and financial data, this omission can cause users to disclose sensitive information without informed consent, creating privacy, confidentiality, and compliance risk.
