Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill clearly sends user prompts and potentially user-supplied images to QuiverAI's external API, but the documentation does not warn users that their content leaves the local environment and is processed by a third party. This can lead to inadvertent disclosure of sensitive prompts, proprietary designs, or private images, especially because the skill is specifically intended to accept user-provided creative inputs.
