Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs sending uploaded media files, messages, and session data to a third-party cloud API, but the user-facing description does not clearly disclose that their content will be transmitted off-platform for remote processing. This creates a privacy and consent risk, especially because users may upload personal or unpublished media under the assumption processing is local or otherwise implicit.
