Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly supports summarizing URLs, local files, and YouTube content using third-party model providers and optional fallback services, but it does not warn users that submitted content may be transmitted off-host. This creates a real privacy and data-handling risk because users may pass sensitive documents or private links assuming processing is local, when the content could be sent to external APIs such as OpenAI, Anthropic, Google, Firecrawl, or Apify.
