Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs automatic upload of generated report contents to DingTalk documents and a DingTalk table, but the skill description and workflow do not require clear user consent or a warning that locally generated analysis will be transmitted to external services. This creates a real data-handling and privacy risk because report contents, conclusions, and metadata may be sent off-platform without an explicit opt-in at execution time.
