Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill explicitly instructs the agent to retain user interests, questions, feedback, and a personal reading list, but provides no notice, consent mechanism, retention limits, or guidance on handling personal data safely. Even if the data seems low sensitivity, it can still reveal detailed profiles of a user's interests and behavior over time, creating privacy and compliance risk if stored or reused unexpectedly.
