Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill exposes a `generate` command that sends user-supplied prompts to an external AI service via OpenAI-compatible API settings, but the documentation does not clearly warn users that their prompt content leaves the local environment. This creates a real privacy and data-handling risk because users may provide sensitive text, proprietary schema descriptions, or internal context under the assumption the tool is purely local.
