Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The skill reads a locally stored Groq API key and uploads extracted audio to Groq's transcription API, but the user-facing description does not clearly disclose this third-party data transfer. This creates a privacy and consent issue because potentially sensitive audio/content is transmitted off-device to an external service.
