Missing User Warnings
Medium
- Confidence
- 98% confidence
- Finding
- The skill explicitly instructs users to send raw text containing highly sensitive data such as email addresses and SSNs to a third-party remote API, but it does not provide a prominent warning that the unsanitized data leaves the local environment before any protection is applied. In a PII-sanitization skill, this context makes the omission more dangerous because users may incorrectly assume sanitization happens locally or before transmission.
