Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill sends user-supplied audio URLs and receives transcription content from a remote third-party service, but it does not clearly warn users that potentially sensitive audio and derived text leave the local environment. This can lead to unintended disclosure of confidential call recordings, PII, or regulated data, especially because the feature is explicitly marketed for bulk processing of up to 500 files.
