Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The scenario instructs the agent to retrieve account profile and fee data, which are user-specific financial details, without requiring an explicit notice or consent step before accessing them. In a conversational agent context, silent retrieval of sensitive account information can violate user expectations, reduce transparency, and increase the chance of unintended disclosure if the request was ambiguous or made in a shared environment.
