Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly demonstrates uploading a local file and sending prompts/media to a third-party service, but it does not provide a prominent user-facing warning that local content and prompt data leave the host environment and are processed externally. In an agent setting, this can cause unintentional disclosure of sensitive images, metadata, or confidential prompt content if users or downstream agents treat the action as purely local processing.
