Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill instructs users to upload cover images and videos and later states the upload endpoint returns a public URL, but it does not clearly warn at the point of use that uploaded media becomes publicly accessible. This can lead agents or users to disclose sensitive, proprietary, or personal media under the mistaken assumption that uploads remain private.
