Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The skill explicitly instructs users to send prompts and an authentication token to a third-party endpoint, but it does not provide a clear warning that prompts, model inputs, and billing/auth data leave the local environment and may be retained in request logs. The later trust statement even says 'No data stored beyond request logs,' which confirms logging but still does not present a prominent privacy warning near the usage examples.
