Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill instructs users to send repository questions through SkillBoss API Hub and notes web scraping/LLM processing, but it does not prominently warn that repository queries and retrieved documentation are transmitted to third-party services. This can lead users to unknowingly disclose sensitive prompts, internal repository names, or other metadata to external processors.
