Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs the system to read uploaded resume files, extract their text, and send that content to a language model without any explicit privacy notice, consent checkpoint, or data-handling constraint. Resumes commonly contain sensitive personal data such as phone numbers, email addresses, employment history, education, and location details, so silent transmission to a model can expose users to unintended data disclosure and compliance risk.
