Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill demonstrates uploading a local file and sending it to a third-party image service without clearly warning that local image contents may leave the user's environment. In an agent setting, this can cause unintentional disclosure of sensitive personal, confidential, or regulated image data if the user or calling workflow does not realize the transfer occurs.
