Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly advertises outcome capture and LLM telemetry, which implies collection and transmission of potentially sensitive prompts, responses, and user-derived data, but provides no privacy notice, consent guidance, or scoping limits. In an agent skill context, this is dangerous because operators may enable the skill without realizing that interaction content and outcomes could be sent to a third-party service.
