Missing User Warnings
High
- Confidence
- 97% confidence
- Finding
- The skill explicitly solicits highly sensitive financial and personal tax data, including screenshots from the tax app, without warning the user about the sensitivity of that information or encouraging minimization/redaction. In context, this is more dangerous because tax screenshots can contain identifiers, employer data, income, deductions, and tax payments that could enable privacy harm, fraud, or downstream misuse if overshared.
