Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- This skill is designed to access and transmit highly sensitive health information to an external API, yet it does not prominently warn users up front that protected health-related data and an API token will be sent to a third-party service. In a health context, lack of explicit disclosure and consent is risky because users may unknowingly expose lab results, medications, conditions, and documents to an external processor.
