Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The README encourages OCR extraction of invoices, travel tickets, and reimbursement documents, which commonly contain personal, financial, and tax identifiers, but it provides no privacy, retention, or handling guidance. In a skill designed to process sensitive documents, this omission increases the risk that users will upload, store, or share regulated data insecurely and assume the workflow is safe by default.
