Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly encourages sharing code, configs, logs, diffs, and secrets with a third-party service, but it does not prominently warn users that this transmits potentially sensitive material outside the local environment. Even if the service uses encryption and supports passwords or expiration, users may still disclose credentials, proprietary code, tokens, or regulated data to an external host without informed consent.
