Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The reference explicitly encourages sending user-supplied media URLs and an optional callback URL to a third-party API, but it does not warn that this discloses those URLs and associated content to PoYo and causes PoYo to make outbound requests to those endpoints. In a skill context, users may assume uploaded or linked assets remain local, so the omission can lead to unintentional privacy leaks, disclosure of internal URLs, or unsafe callback usage.
