Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The documentation tells users to run a script that submits their prompt, API key-authenticated request metadata, and any provided image URLs to a third-party service, but it does not clearly disclose that external transmission occurs. In a skill context, users may paste sensitive prompts or internal URLs assuming the action is local, so the missing notice creates a meaningful privacy and data-handling risk.
