Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill instructs operators to upload user voice recordings to ElevenLabs for speech-to-text processing without any consent flow, privacy notice, retention discussion, or warning that third-party processing occurs. This creates a real privacy and compliance risk because potentially sensitive user audio is transmitted off-platform, and the query parameter enable_logging=true may further increase data exposure through provider-side logging.
