Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly advertises `llm-provider` and `message-send` capabilities, which imply data may be transmitted to external models or messaging endpoints, but it does not warn users about possible outbound communication, data sharing, or privacy implications. In an agent/MCP context, this omission is security-relevant because users may provide sensitive prompts or documents without realizing they could leave the local environment.
