Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The example sends personally identifiable information including name, email, and home address to an external booking API, but the documentation gives no privacy notice, retention guidance, minimization advice, or warning that agents should obtain user consent before transmission. In an agent skill, this can lead to unnecessary or premature disclosure of sensitive user data to a third party, especially if implementers copy the example flow directly.
