Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill documentation specifies sending raw user input to an external model routing service, but it does not mention any notice, consent, minimization, or handling of sensitive mental-health-related content. Because users may disclose highly personal crisis or emotional information, undisclosed network transmission creates a meaningful privacy and data-governance risk even if the feature is not overtly malicious.
