Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill explicitly recommends capturing user emails and progressively collecting profile attributes, but provides no guidance on consent, lawful basis, retention, notice, or secure handling of personal data. In a marketing-focused skill, this omission can normalize privacy-noncompliant lead collection and lead downstream agents or users to implement forms and tracking that violate internal policy or regulations such as GDPR/CCPA.
