Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill instructs the agent to send user text and a cloned voice identifier to an external API using a bearer token, but it does not require explicit user-facing disclosure or consent before transmission. This can lead to unintended sharing of potentially sensitive text content and voice-linked identifiers with a third-party service.
