Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly instructs users to send prompts and text content to a third-party remote API, but it does not clearly warn that user data will leave the local environment and be processed by an external service. In an agent-skill context, this can lead to accidental disclosure of sensitive prompts, documents, or secrets if operators assume processing is local.
