Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill uploads the user-supplied file to a third-party LLMWhisperer API, but the description does not clearly disclose that document contents leave the local environment. This creates a real privacy and compliance risk because users may process sensitive PDFs or images under the mistaken assumption that extraction happens locally.
