Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs users to send arbitrary title/content data to a remote HTTP endpoint identified by raw IP address, but it does not warn that user input will leave the local environment and be transmitted to a third-party server. Because the feature also appears tied to paid invocation, users may unknowingly disclose sensitive marketing drafts or internal copy while triggering billable requests without informed consent.
