Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill directs the bot to create and query CRM records tied to a Telegram user without any notice, consent flow, or explanation of what data is stored and why. This creates a privacy risk because users may unknowingly have their identity, interests, and sales-stage data profiled and retained, which can violate data protection expectations or legal requirements.
