Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The README explicitly instructs users to upload their PDF and bearer token to a third-party service, but it does not clearly warn about privacy, retention, jurisdiction, or trust implications of transmitting potentially sensitive documents off-system. This is dangerous because users may assume the skill operates locally or is inherently 'safe' while confidential PDF contents and credentials are sent to an external provider.
