Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs users to send image URLs to a third-party remote endpoint but does not disclose the privacy and data-sharing implications. Even if only URLs are sent, those URLs may contain sensitive information, internal hostnames, signed access tokens, customer identifiers, or links to non-public assets, and the service operator will learn what resources the user is processing.
