Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs the agent to collect and reproduce sensitive workplace and personal information such as site addresses, principal contractor details, contact names, phone numbers, first aider identity, and emergency contacts, but it provides no privacy notice, data-minimization guidance, or instruction to avoid unnecessary retention/sharing. In practice, this can cause over-collection and exposure of personal or sensitive operational details in chat logs, generated documents, or downstream systems, especially when the SWMS is produced for broad circulation.
