Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The skill advertises user search and per-user activity retrieval capabilities that can expose profile attributes, identifiers, and behavioral timelines, but it provides no privacy guidance, access-control expectations, or data-minimization constraints. In an agent setting, this omission increases the likelihood of inappropriate querying or disclosure of personal data, especially if the tools are used on arbitrary users without clear authorization checks.
