Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill repeatedly instructs users and agents to upload PDFs and query extracted content through a third-party remote service, but it does not include any privacy, retention, sensitivity, or data-handling warning. In an agent context, that omission is risky because users may send confidential PDFs, regulated data, or internal documents off-platform without informed consent.
