Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs sending user-provided reaction images to a third-party HuggingFace Space, but it does not warn that uploaded images and embedded metadata may leave the local environment and be processed by an external service. This creates a real privacy and data-governance risk, especially because chemistry reaction images may contain proprietary research, confidential process information, or regulated data.
