Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill documents use of OpenAI-backed image description/OCR features but does not clearly warn users that document or image contents may be transmitted to a third-party API for processing. In an agent setting, users may reasonably assume conversion is local, so this omission can lead to unintended disclosure of sensitive file contents, especially for PDFs, presentations, and embedded images.
