Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill explicitly instructs users to send prompts and optional reference image URLs to a third-party API, but it does not clearly warn that user-provided content will leave the local environment and be processed by an external service. This can lead to unintended disclosure of sensitive prompts, private image URLs, or internal resource links if users assume the skill operates locally or do not understand the data-sharing implications.
