Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill instructs users to supply an ElevenLabs API key and use cloud TTS functionality, but it does not clearly disclose that submitted text and authentication credentials are used to interact with a third-party service. This can cause users to unknowingly send sensitive prompts or content off-device, which is a real privacy and data-handling risk in an agent skill context.
