Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill explicitly documents retrieval of lead form submissions, which can contain personally identifiable information such as names, emails, phone numbers, and other submitted answers, but provides no warning or handling guidance for sensitive data. In a data-access skill, omission of privacy safeguards increases the chance the agent will retrieve, expose, summarize, or mishandle personal data without user confirmation or minimization.
