Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly tells users to upload images, fonts, or other assets and notes that the resulting files are publicly accessible for 24 hours, but it does not prominently warn against uploading sensitive or private content. In an agent context, users may assume uploads are temporary and scoped to their task, so this can lead to unintentional data exposure of proprietary documents, internal branding assets, or personal information.
