Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The README instructs users to send free-form prompts, optional reference-image identifiers, and an API token to a third-party image-generation service, but it does not warn that this data leaves the local environment and may be stored, logged, or reused by the provider. In an agent-skill context, users may paste sensitive personal, proprietary, or identifying content into prompts or supply references tied to private images, so the lack of disclosure creates a meaningful privacy and data-handling risk.
