Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The README explicitly instructs users to upload reference images and then use the returned URL in subsequent API calls, but it does not warn that user-supplied images and prompts are being transmitted to a third-party service. In an agent-skill context, this can cause inadvertent exfiltration of sensitive or proprietary content because users or downstream agents may assume the operation is local or privacy-preserving.
