Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly states that the full AuditData JSON is sent to OpenAI, but it does not disclose or constrain what sensitive content may be included in that payload. Marketing audit data can contain business-sensitive information, internal website findings, competitor intelligence, identifiers, and possibly personal data; sending it to an external AI provider without clear warning, minimization, or redaction guidance creates a real data exposure risk.
