Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly instructs saving raw API JSON and downloaded image artifacts to disk, but provides no warning, consent step, retention guidance, or constraints on where data is written. Even if the content is not highly sensitive, silent local file writes can create privacy, persistence, and disk-usage risks in agent environments, especially when output paths are user-controlled or shared.
