Missing User Warnings
High
- Confidence
- 97% confidence
- Finding
- The skill is explicitly designed to monitor all private chats, @mentions, whitelisted group chats, documents, and calendar events, but it provides no clear consent flow, privacy notice, data minimization boundaries, or disclosure to affected parties. This creates a real privacy and over-collection risk because a broad autonomous agent can ingest highly sensitive communications and work artifacts beyond what is necessary for a specific task.
