Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly sends user prompts to an external API endpoint but does not warn users that their input will leave the local system and be transmitted to a third-party service. This creates a real privacy and data-handling risk because users may include sensitive, proprietary, or regulated information in prompts without informed consent.
