Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill directs users to authenticate with RunAPI and submit image-generation or editing requests, but it does not disclose that prompts, images, and related inputs will be sent to a third-party external service. This creates a real data-handling and privacy risk because users or downstream agents may send sensitive text or images without informed consent or appropriate controls.
