Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill instructs sending health-related procedure queries together with insurance and optional location data to a third-party API, but it does not give an explicit privacy warning or minimization guidance. Even if the API is legitimate, these fields can reveal sensitive personal or medical context, so omission of disclosure and caution is a real privacy/security weakness.
