Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs the agent to read local files, upload reference images and story content to an external Google-hosted tool, and save generated output locally, but it does not provide a clear user-facing warning about data exfiltration, third-party processing, or filesystem side effects. In context, this is genuinely risky because the skill depends on an already-authenticated browser profile, which lowers friction for unintended disclosure of local content to an external service.
