Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly instructs users to send prompts and, elsewhere in the file, source image URLs to a third-party API but does not warn that user content will leave the local environment and be processed by an external service. This can lead to inadvertent disclosure of sensitive prompts, private image locations, or regulated data if users assume the skill is purely local.
