Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill states it is backed by the Satoshi API and works with zero config, but it does not clearly warn users that Bitcoin-related queries will be sent to an external third-party service. This creates a privacy and data-handling risk because wallet addresses, transaction identifiers, PSBT-related metadata, and usage patterns may be disclosed to an external provider without informed user consent.
