Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill explicitly instructs the agent to upload a user's food image to a remote service immediately, before any user-facing notice or confirmation. Images can contain sensitive health, location, or incidental personal information, so transmitting them automatically creates a privacy risk and weakens meaningful user consent.
