Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly routes user documents through Zhipu's cloud OCR service, but the documentation does not clearly warn that document contents leave the local environment and are sent to a third party. For an agent skill handling invoices, scans, and other potentially sensitive documents, this creates a real privacy and compliance risk because users or downstream operators may assume local-only processing.
