Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill asks users to upload PDF documents for processing by a third-party API, but it does not clearly warn that document contents leave the local environment and are sent to an external service. This creates a meaningful privacy and data-handling risk, especially because the stated use cases include contracts, research papers, and business documents that may contain sensitive or regulated information.
