Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill repeatedly instructs agents to send prompts, documents, audio, phone numbers, email content, and other user-supplied data to https://api.heybossai.com and explicitly routes requests across multiple third-party providers, but it does not warn about data disclosure, retention, provider sharing, or privacy implications. This creates a real security and privacy risk because agents or users may unknowingly transmit sensitive content off-platform to multiple external services.
