Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill explicitly instructs users to upload local images as base64 data URLs and to submit remote image URLs to an external API, but it provides no warning that images may contain sensitive personal, financial, medical, or proprietary information. In an image-recognition skill, this omission is significant because users are encouraged to send raw visual data off-device, increasing the risk of inadvertent disclosure to a third-party service.
