Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The workflow instructs users to invoke the skill with an image and custom ROI payload sent to an external endpoint (`ep-xxxx-yyyy`), but it does not explicitly disclose that the image and associated metadata leave the local environment. In a vision-analysis skill, images may contain sensitive operational, personal, or security-monitoring data, so omission of this disclosure can cause unintended data exfiltration and misuse in privacy-sensitive contexts.
