Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly supports processing local HTML files and URLs through a token-authenticated external CLI/API, but it does not clearly disclose that submitted content may leave the local environment and be sent to MinerU's service. This creates a real data-exposure risk because users may pass sensitive local files or internal URLs under the assumption the conversion is purely local.
