Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- This script sends user-supplied person, company, domain, role, and geo query data to a third-party Prismfy search API, but the script itself provides no runtime disclosure, consent gate, or minimization warning before transmission. In a contact-discovery skill, that means potentially sensitive identifiers about outreach targets are exported off-host by default, which is a real privacy and data-governance risk even if it is core functionality.
