Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill directs users to configure external MCP endpoints and send document identifiers, questions, and potentially extracted content to OkraPDF services, but it does not clearly warn that these prompts and metadata leave the local environment. This can lead to unintentional disclosure of sensitive research interests, internal analysis prompts, or other query content to a third-party service.
