Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill instructs users to send PR-linked ticket identifiers and related metadata to third-party services (Jira and Linear) using authenticated API calls, but it does not warn that repository context, ticket references, and potentially sensitive workflow metadata will be transmitted externally. In a PR review skill, this is more dangerous because users may run the commands against internal projects and assume all processing is local, creating an avoidable data disclosure and compliance risk.
