Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The README promotes proxying API calls with automatic billing but does not clearly warn that prompts, files, or other user-supplied data may be transmitted to third-party services and may incur real charges. In an agent skill context, this omission is risky because users may assume local or trusted execution while the agent can instead send sensitive data externally and spend account credits.
