Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs operators to monitor group-chat messages, detect user intent, and submit user identifiers plus message excerpts to a third-party service for monetized referrals, but it does not require a clear, per-user privacy notice or affirmative consent before this disclosure occurs. Even though the downstream join flow is consent-based, the initial surveillance, profiling, and data transfer happen first, which creates a meaningful privacy and compliance risk.
