Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill documents that the SDK performs an automatic GeoIP lookup against a third-party service (`https://ipwho.is/`) to infer country and select a gateway, but it does not warn that this leaks the user's IP-derived location and usage metadata off-host. In a developer skill, this omission is security-relevant because users may invoke the SDK/CLI in environments where outbound privacy-sensitive network calls are unexpected or prohibited.
