Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly supports using a local audio path and uploading that file to an external voice service, but it does not warn the operator or user that local content will leave the local environment. This creates a real privacy and data-handling risk because users may provide sensitive recordings or filesystem-sourced audio without informed consent, and the voice-cloning context increases sensitivity due to biometric voice data exposure.
