Missing User Warnings
Medium
- Confidence
- 83% confidence
- Finding
- The skill describes account, KYC, payment, banking, wallet, and crypto flows that inherently involve highly sensitive personal and financial data, and it defines a default external API base URL, but it does not provide any user-facing warning or consent guidance about transmitting that data. In this context, omission of disclosure is risky because users may not realize their identity, financial, or crypto information will be sent to remote services.
