Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The script sends the user-provided question to a remote Prana service over the network, but there is no explicit user-facing disclosure at execution time that potentially sensitive financial-analysis prompts will leave the local environment. In a skill context that mandates remote agent invocation, this behavior is expected, but it still creates a real privacy and data-handling risk if users include confidential company, customer, or internal research data without informed consent.
