Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill is explicitly designed to poll message channels and send replies to a remote service using an API key, which means user messages and channel metadata are transmitted off-host to a third-party API. While this appears to be the intended functionality rather than malicious behavior, the documentation does not clearly disclose privacy implications, data handling expectations, retention, or guidance on minimizing sensitive data exposure, which can lead operators to deploy it without informed consent or proper controls.
