Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly tells the agent to upload a user-provided local file to a public cloud URL, but it does not require an explicit consent/privacy warning before transmission. This creates a real data-handling risk because local media may contain sensitive content or metadata, and the upload produces an externally hosted URL that could expose user data beyond the local environment.
