Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill requires collecting breach-assessment inputs that may reflect sensitive incident details and sending them to a third-party API, but it does not clearly warn the user that this information will leave the local environment. In a security context, breach details can themselves be confidential, regulated, or legally sensitive, so silent transmission creates real privacy, contractual, and compliance risk.
