Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill asks users to provide full bank card numbers and sends them to JisuAPI, but the user-facing description does not clearly warn that this sensitive financial data will be transmitted to a third-party service. This creates a privacy and data-handling risk because users may disclose card numbers without informed consent, and card metadata plus validity information can be sensitive even if not sufficient alone for fraud.
