Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill sends raw user-supplied medical questions, which may contain sensitive health information, to a remote third-party API endpoint without any explicit consent notice, privacy warning, minimization, or redaction step in the code path. In a medical context this is materially risky because callers may unknowingly transmit protected or highly sensitive personal data outside their local environment.
