Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The usage documentation encourages users to submit arbitrary prompts for image generation but does not clearly warn that those prompts are transmitted to Zhipu's external API service. Users may unknowingly send sensitive, proprietary, or personal data off-platform, which is a privacy and data-handling risk made more relevant because the skill is explicitly designed to forward free-form text to a third party.
