Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill explicitly instructs loading credentials from `~/code/.env` and using them for third-party ASR services, but it provides no user-facing notice that local secrets and user audio will be sent to external providers. In an agent setting, this can cause silent use of sensitive API keys and external processing of potentially confidential media without informed consent or clear scope controls.
