Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs sending the user's full message to a public API for entity recognition before any token-specific query, which can expose sensitive user data unnecessarily. Even if the API is legitimate and unauthenticated, forwarding raw user text without minimization, consent, or a privacy warning creates a real privacy and data-handling risk.
