Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs sending generated chart images to a hard-coded Telegram target, which can cause unintended exfiltration of user-requested outputs or locally generated artifacts to an external recipient without user confirmation. Even though chart images are not inherently sensitive, embedding a fixed recipient in the skill creates a dangerous data-flow pattern and normalizes outbound sharing without privacy checks or consent.
