Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly states it is powered by an external API and later shows that user-provided file text is sent to a remote `/v1/pilot` endpoint, but it does not clearly warn that the file contents leave the local system. This creates a real confidentiality risk because users may pass sensitive drafts, notes, or proprietary text without realizing they are being transmitted to a third party.
