Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs sending user prompts plus reference/product images to remote Supabase function endpoints, but it provides no user-facing notice, consent step, retention information, or guidance about sensitive image content. This creates a real privacy and data-handling risk because users may unknowingly transmit proprietary, personal, or regulated content to a third-party service.
