Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly describes use of a cloud OCR model but does not clearly warn users that supplied images or image URLs will be transmitted to a third-party remote service for processing. This can lead to unintended disclosure of sensitive screenshots, documents, or private URLs, especially because OCR inputs commonly contain credentials, personal data, or internal business information.
