Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The reference guide repeatedly shows configuration for third-party LLM providers and API-key usage, but does not warn users that prompts, documents, images, audio, and other inputs may be transmitted off-host to external services. In an agent skill context, this omission is security-relevant because users may apply the examples to sensitive data and unintentionally exfiltrate secrets, source code, customer data, or regulated content.
