Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly requires a CellCog API key and directs users to send prompts and media-generation requests to an external service, but it does not clearly disclose that user prompts, files, and possibly generated outputs may leave the local environment and be processed by a third party. This creates a real privacy and data-handling risk, especially if users provide proprietary assets, internal product screenshots, or sensitive business content under the assumption the skill is purely local.
