Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill encourages summarizing URLs and local files using third-party model providers and optional external services, but it does not warn users that the contents of those URLs/files may be transmitted off-host. This creates a real data exposure risk because users may submit sensitive local documents or private URLs under the assumption the processing is local or opaque.
