Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs the agent to record all transactions to a connected Google Sheet, but the skill text provides no user-facing notice, consent flow, or data-minimization guidance. In a WhatsApp ordering context, transaction logs can contain names, phone numbers, order contents, allergy notes, and timestamps, so silent transmission to an external sheet creates a meaningful privacy and compliance risk.
