Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs users to send prompts to a third-party LLM API but does not warn that prompt contents will leave the local environment and be processed by an external service. This can cause inadvertent disclosure of sensitive data, especially in agent settings where prompts may contain private documents, credentials, or internal context.
