Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly describes sending task content, draft outputs, self-reviews, and context across multiple third-party models, but it does not warn users that sensitive prompts or project data may be disclosed to multiple external providers. In an orchestration skill, this omission is material because the whole pattern encourages broad replication of potentially confidential data, increasing privacy, compliance, and data-governance risk.
