Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly relays user prompts to third-party OpenAI-compatible endpoints and later documents that sessions are cached locally, but the description does not warn users that their prompts and conversation history may leave the local environment and be stored on disk. This omission can cause users to send sensitive data under the false assumption that the tool is purely local or ephemeral, increasing privacy and compliance risk.
