Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill instructs the agent to establish a backend connection and upload user media, including obtaining an anonymous token and creating a remote session, without requiring an explicit user-facing notice or consent for data transfer. Because users may provide private images and videos, silently transmitting them to a third-party cloud service creates a meaningful privacy and data-handling risk.
