Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs users to provide team data including headcount, tenure distribution, recent departures, eNPS scores, and compensation bands, which can include sensitive HR and compensation information. Because it gives no minimization, anonymization, consent, retention, or secure-handling guidance, users may submit personal or confidential workforce data into an agent workflow inappropriately, creating privacy, confidentiality, and compliance risk.
