Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill directs agents to send images, annotations, bot identifiers, and Lightning payment artifacts to a third-party service but does not clearly warn that this data leaves the local environment and may be stored, logged, or published. In an agent context, this can lead to unintended disclosure of sensitive media, metadata, or payment-related tokens because users may assume the skill is operating locally or with minimal sharing.
