Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill explicitly routes user queries to Cue's external API and instructs users to store an API key in ~/.cue/config.json, but it does not present a clear upfront warning about third-party transmission and local secret storage. This can mislead users into sending sensitive fund research prompts or credentials without informed consent, increasing privacy and secret-handling risk.
