Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly states it sends code to three external AI agents, but it does not present a prominent privacy/security warning about transmitting potentially sensitive source code, diffs, secrets, or proprietary data to third-party services. In a security-review skill, users may reasonably assume safer handling, so the missing disclosure increases the risk of unintended data exfiltration to external providers.
