Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to send user prompts and local image files to Google/Gemini via `yummycli gemini veo`, but it does not warn the user that their text and uploaded local media will leave the local environment and be transmitted to a third-party service. This creates a privacy and data-handling risk, especially if users provide sensitive prompts or images assuming processing is local.
