Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill is explicitly designed to send prompts, task details, and human responses through an external service and onward to external humans, but it does not prominently warn that sensitive, proprietary, or personal data may be disclosed outside the agent's trust boundary. In a human-in-the-loop workflow, this omission can cause accidental privacy breaches because users may assume content stays within the agent or API provider rather than being exposed to third-party workers.
