Missing User Warnings
Medium
- Confidence
- 84% confidence
- Finding
- The skill includes an API integration example that sends arbitrary `messages` to a third-party endpoint, but it does not explicitly warn users that prompts, test cases, or production data may be transmitted off-platform. In an evaluation skill, those messages can easily contain sensitive benchmark data, proprietary prompts, or user content, so the lack of a clear disclosure and data-handling guidance creates a real privacy and compliance risk.
