Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill explicitly instructs users to configure API credentials and use external image-generation providers, but it does not warn that prompts, source images, masks, and edited content will be transmitted to third-party services. This can lead users to unknowingly send sensitive or proprietary data off-system, which is a real privacy and data-handling risk in an image generation skill whose core purpose is remote inference.
