Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill encourages sending prompts and image URLs to an external service via the inference.sh CLI, but it does not prominently warn users that their text prompts and referenced images may be transmitted to a third-party system. In a skill that handles user-supplied creative content, this creates a real privacy and data-handling risk, especially if users provide sensitive images, internal designs, or confidential prompts.
