Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill repeatedly encourages sending arbitrary 'complex analysis' prompts to three third-party models via OpenRouter, but it does not clearly warn users that their prompt contents may be transmitted to multiple external providers. In an agent setting, this can cause sensitive business, personal, or proprietary data to be disclosed more broadly than the user expects, multiplying privacy and compliance risk.
