Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- This documentation acknowledges that a host LLM provider may transmit prompt context to a remote model, but it stops short of giving a clear user-facing warning before sensitive biometric data is discussed. In a health-data skill, that omission can lead users or operators to unknowingly expose highly sensitive personal health information to third-party model providers, creating privacy and compliance risk even if the skill itself performs only local reads.
