Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill sends user-provided Markdown to a third-party service and returns a publicly accessible URL valid for 90 days, but it does not clearly warn users about this data exposure at the point of use. This creates a real confidentiality and privacy risk because agents may upload sensitive internal content, believing the operation is local or private, when the resulting document is published to an external storage location.
