Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill explicitly demonstrates uploading local image files and prompts to a third-party remote API, but it does not warn users that local content may contain sensitive or private data. In this context, the omission is security-relevant because users may assume the examples are routine and fail to notice that personal images, masks, and prompts are being transmitted off-device.
