Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The review method sends user-supplied code into an LLM-driven multi-agent workflow without any explicit user-facing notice, consent, or data-handling boundary. In a code review skill, submitted code may contain proprietary logic, secrets, credentials, or customer data, so undisclosed transmission to an external model provider creates a real confidentiality and compliance risk.
