Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill is designed to process highly sensitive bank transaction data, counterparties, company names, and identifiers, yet it provides no confidentiality warning, data minimization guidance, or handling constraints. In this context, users may unknowingly expose regulated financial or personally identifiable business data to the tool, increasing the risk of improper disclosure, unsafe storage, or unauthorized downstream sharing.
