Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill is designed to retrieve and output employee directory data, including employee IDs, landlines, and mobile numbers, without any privacy notice, access-control check, or data-minimization step. In the context of an enterprise address book, this increases the risk of unnecessary disclosure of internal PII to users who may not have a legitimate need to access all requested fields.
