Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill instructs users to upload raw PDF content to a third-party API and shows that the service returns a hosted download URL, but it does not warn users that document contents leave the local environment and may be stored or exposed externally. This creates a real privacy and data-handling risk, especially for sensitive PDFs containing business, legal, financial, or personal information.
