Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly requires an OPENAI_API_KEY but does not disclose that user queries and retrieved document content may be sent to an external API provider. In a RAG skill over local files, this omission is security-relevant because users may assume processing is local while sensitive local document contents could be transmitted off-host.
