Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill recommends `ramalama serve <model>` and discusses serving an OpenAI-compatible endpoint, but it does not warn that exposing a local inference API can unintentionally make model access or submitted prompts available to other local users or network peers, depending on bind defaults and container/runtime configuration. In a skill specifically about running agents and serving models, omission of exposure guidance materially increases the chance of accidental service exposure.
