Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The documentation encourages sending user prompts and images to a third-party API endpoint, but it does not clearly warn users that their content will leave the local agent boundary and be processed by an external provider. In an agent setting, this can lead to inadvertent disclosure of sensitive prompts, documents, screenshots, or embedded secrets.
