Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The README explicitly describes sending symptom and health-related data to a remote third-party API, but it does not provide any user-facing privacy notice, data handling disclosure, retention policy, or consent guidance. Because the skill processes potentially sensitive medical information, this omission increases the risk of unintended disclosure and non-compliant handling of personal health data.
