Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill advertises web search and image understanding features that inherently send user-supplied queries, image URLs, and potentially local file references to a third-party MiniMax service, but it does not clearly disclose that data leaves the local environment. This can mislead users into sharing sensitive prompts or local-path information without informed consent, especially in an agent workflow where tool invocation may feel seamless.
