Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill documentation instructs sending user-supplied images to a model API endpoint, including an internal HTTP service, without any explicit privacy notice, consent step, or data-handling disclosure. If users provide sensitive images, this can result in unintended transmission of personal or confidential data to backend services, especially since the examples normalize use of remote inference without surfacing transfer risks.
