Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly supports summarizing URLs, local files, and YouTube content via external model providers and optional fallback services, but it does not warn users that submitted content may be transmitted off-host. This creates a real privacy and data-handling risk because users may pass sensitive documents, internal URLs, or media under the assumption processing is local, when the tool is actually API-backed.
