Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill documents token setup and use of a third-party CLI/API, but it does not clearly warn users in the main skill description or usage guidance that OCR may transmit document contents to an external MinerU service. For a document-processing skill, this omission can cause users to send sensitive legal, office, or archival material off-host without informed consent, creating confidentiality and compliance risk.
