Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly promotes persistent identity, long-term memory, and use of external API endpoints, but it does not disclose that user data and conversation context may be transmitted to a third-party service or retained over time. In an agent ecosystem, this omission can lead operators to enable the skill without informed consent, increasing the risk of privacy violations, policy noncompliance, or unintended exposure of sensitive data.
