Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill sends raw user-provided novel content and title to an external API endpoint built from environment configuration, with no disclosure, consent check, minimization, or destination validation. This creates a real data-exposure risk because users may submit unpublished or sensitive text, and the code provides no transparency or safeguards before transmitting it off-platform.
