Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs users to send invoice/receipt image URLs to a remote third-party endpoint and receive extracted financial document data, but it does not clearly warn that potentially sensitive business and financial information leaves the local environment. Invoices and receipts commonly contain personal data, billing details, tax IDs, addresses, and payment information, so omission of a prominent disclosure can lead to unintentional data exposure and non-compliant handling of sensitive documents.
