Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to proactively pitch background ingestion of highly sensitive data such as health, location, and calendars, and to offer persistent logging of agent interaction details into the user's datastore. Even though the text includes privacy warnings and asks for permission, combining onboarding persuasion with requests to enable sensitive collection increases the risk of over-collection, consent fatigue, and disclosure of intimate behavioral data beyond what is necessary for intent discovery.
