Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs sending user-provided SVG content, URLs, and an API key to a third-party service, but it does not clearly warn that the submitted data leaves the local environment or describe how that external service will store, process, or retain it. This creates a real privacy and secret-handling risk, especially if users paste sensitive SVGs, internal URLs, or reusable API keys assuming the conversion is local or first-party.
