Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill sends VIN and parts-code data to an external third-party API but does not warn users that this information leaves the local environment. VINs can be sensitive business or vehicle-identifying data, so omission of a privacy notice can lead to unintended disclosure, compliance issues, or use of regulated/customer data without informed consent.
