Missing User Warnings
Medium
- Confidence
- 77% confidence
- Finding
- The skill requires a CELLCOG_API_KEY and encourages use of a remote service, but it does not clearly warn users about credential handling, external data transmission, or the sensitivity of prompts/files sent to the provider. In an agent setting, this can lead users to unknowingly transmit proprietary content or mishandle API secrets.
