Missing User Warnings
Medium
- Confidence
- 84% confidence
- Finding
- The skill discloses in the manifest that prompts and image URLs are sent to Meshy's API, but it does not clearly warn users at interaction time that local images or generation prompts they provide will leave the machine. In a skill that accepts user-supplied files and creative prompts, missing just-in-time disclosure can lead to unintended transmission of sensitive or proprietary content to a third party.
