Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill includes an example that base64-encodes a local image file and sends it to a remote MiniMax API, but it does not clearly warn that local file contents leave the machine and are disclosed to a third party. This can cause unintended exfiltration of sensitive images, screenshots, or documents if users treat the example as routine local analysis.
