Missing User Warnings
High
- Confidence
- 95% confidence
- Finding
- The skill encourages persistent storage of customer emails, preferences, support history, and plan information in a third-party backend without clear privacy warnings, consent requirements, data minimization guidance, retention limits, or compliance guardrails. In context, this is dangerous because the skill is specifically designed to collect and transmit customer-linked personal data, increasing the risk of unauthorized disclosure, policy violations, and regulatory noncompliance.
