Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs users to submit document URLs, upload files via presigned URLs, and process them through a third-party MinerU service, but it does not warn that potentially sensitive documents will leave the local environment. This creates a real privacy and data-governance risk because users may unknowingly transmit confidential papers, internal documents, or regulated data to an external processor.
