Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to upload receipt images/PDFs to a third-party API, but it does not require an explicit user-facing consent or privacy warning before transmitting potentially sensitive financial and personal data off-device. Receipts can contain names, merchant locations, partial payment details, loyalty data, and itemized purchases, so silent exfiltration to an external service creates a meaningful privacy and compliance risk.
