Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs users to send prompts and text to a third-party API but does not provide any warning about data leaving the local environment or the privacy implications of transmitting potentially sensitive content. In a skill context, omission of this disclosure can lead users or downstream agents to unknowingly exfiltrate confidential prompts, documents, or personal data.
