Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill includes a concrete example that sends user-supplied video processing requests to a remote API using a bearer token, but it does not explicitly disclose that footage and prompts are transmitted off-host for third-party processing. Users may unknowingly submit sensitive or regulated video content, creating privacy, confidentiality, and compliance risk.
