Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill sends either local file contents or user-supplied remote file URLs to a third-party OCR API, but the CLI does not clearly warn users that their data will leave the local environment. In a document-processing skill, this matters because inputs may contain sensitive business, personal, or regulated data, creating confidentiality and compliance risk even though the transmission is part of intended functionality.
