Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill explicitly instructs users to upload local files and submit image URLs to a third-party service but does not clearly warn that user-provided content will leave the local environment and be transmitted to Keevx-controlled infrastructure. This creates a privacy and data-handling risk because users may unknowingly send sensitive local images or internal URLs to an external API.
