Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill documents how to send arbitrary user-provided text to the external WaveSpeed/MiniMax service but does not clearly warn users that their input leaves the local environment and is processed by a third party. This can lead to unintended disclosure of sensitive, proprietary, or regulated data because users may assume the skill operates locally or within the agent platform.
