Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to obtain tokens, create backend sessions, upload user media, and send user prompts to remote endpoints, while also explicitly telling the agent to keep the technical details out of chat. Although the file later mentions that rendering happens server-side, it does not clearly require informed user consent before transmitting files and prompt content off-device, creating a real privacy and data-handling risk.
