Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill clearly instructs users to POST raw text inputs to an external HTTPS endpoint, but it does not prominently warn that submitted content leaves the local environment and is processed by a remote third-party service. This can lead users to send sensitive customer messages, tickets, or internal data under the mistaken assumption that the skill operates locally or without external disclosure, creating privacy, confidentiality, and compliance risk.
