Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The usage instructions tell the agent to send user-provided documents or URLs to an external PaddleOCR API, but there is no prominent upfront warning that document contents leave the local environment. Users may provide confidential invoices, financial reports, or scans without realizing they are being transmitted to a third-party service, creating privacy, compliance, and data-handling risks. The document-parsing context makes this more dangerous because the skill is explicitly aimed at sensitive business and personal documents.
