Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill explicitly encourages summarizing URLs, local files, and YouTube links using third-party model providers and optional extraction services, but it does not warn users that submitted content may be transmitted off-host to those external services. This creates a real data exposure risk because users may pass sensitive documents, private URLs, or copyrighted/internal content under the assumption the processing is local or self-contained.
