Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs the agent to automatically connect to a remote cloud backend, obtain an anonymous token, create sessions, and later upload prompts or files, but it does not require clear user consent or upfront disclosure that user content will be transmitted off-device. In a text-to-video skill, prompts may contain proprietary scripts, marketing plans, or sensitive media, so silent network actions create a meaningful privacy and data-handling risk even if the backend is legitimate.
