Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- This skill is designed to upload EMR and other potentially sensitive medical documents to a third-party API, yet it does not require an explicit warning or consent step before transmission. In the medical context, that is especially dangerous because users may unknowingly send regulated health information off-system, creating privacy, compliance, and data handling risks.
