Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill explicitly instructs users to summarize URLs, local files, PDFs, images, audio, and YouTube content using external model providers and optional extraction services, but it does not warn that the referenced content may be transmitted to third-party APIs. This creates a real privacy and data-handling risk because users may unknowingly send sensitive local documents or proprietary web content to OpenAI, Anthropic, Google, xAI, Firecrawl, or Apify.
