Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly allows optional user-provided `q` and `prompt` values to be forwarded to a local backend endpoint, but it provides no requirement to warn the user, obtain consent, or minimize sensitive data before transmission. This creates a real privacy and data-handling risk because users may unknowingly send secrets, personal data, or confidential prompts to the merchant backend during a premium-action request.
