Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill sends and processes personal scheduling data such as names, email addresses, staff identifiers, notes, and appointment details through external API endpoints, but it does not warn users or downstream agents that this data leaves the local environment. This can lead to unintentional disclosure of personal or business-sensitive information, especially when autonomous agents pass customer data to third-party services without explicit consent or data-handling awareness.
