Missing User Warnings
- Category
- Not specified by scanner
- Confidence
- 94% confidence
- Finding
The skill explicitly states it makes outbound calls to Anthropic and OpenAI judge models, but it does not clearly warn users that candidate outputs, ground truth, source text, and possibly other evaluation artifacts may be sent to third-party providers. In an evaluation workflow, those inputs often contain proprietary prompts, model outputs, customer data, or sensitive internal content, so missing disclosure can lead to unintentional data exfiltration and compliance/privacy violations.
- Content
