Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill explicitly states it uses the Odesli/song.link API to resolve international music links and fetch album artwork, which means user-supplied URLs and associated music metadata are sent to a third-party service. The documentation does not clearly warn users or calling agents about this external data sharing, so potentially sensitive listening preferences, shared links, or metadata could be disclosed without informed consent.
