Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The documentation instructs users to make media publicly fetchable over HTTPS so TikTok can retrieve it, but it does not explicitly warn that this exposes the media to anyone with the URL and may create privacy, confidentiality, or premature disclosure risks. In a social-post scheduling skill, users may upload embargoed, internal, or personal media, so omitting that warning can lead to unintended public exposure even if the platform requirement itself is legitimate.
