Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly demonstrates base64-encoding a local audio file and sending it to a third-party API, but it does not warn that potentially sensitive voice content leaves the local environment. In an STT skill this behavior is expected, but the lack of disclosure and privacy guidance is still a real security/privacy issue because users may unknowingly transmit confidential audio.
