Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly instructs the agent to immediately fetch weather using an inferred city from conversation context, including the user's location, without asking for confirmation. This creates a privacy risk because the agent may derive and act on location-sensitive data the user did not explicitly request in that invocation, increasing the chance of unintended disclosure or over-collection.
