Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill clearly sends user-supplied topics, optional context, workspace slug, and brand URL to the external Kitful API, but the description does not prominently disclose that data leaves the local environment. Users may provide sensitive business context or proprietary prompts without realizing they are transmitted to a third-party service, creating privacy and data-handling risk.
