Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs users to open a real browser and continuously save same-origin raw responses to the Desktop, but it does not present a prominent warning that this may capture authenticated HTML, API responses, personal data, tokens, or other sensitive account content during normal browsing. Because the output is automatically persisted locally and continuously during user interaction, the missing warning and consent framing creates a real privacy and data-handling risk rather than a purely cosmetic documentation issue.
