Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill guides the agent through collecting travelers' names, dates of birth, gender, contact details, and generating a checkout URL for a real purchase, but it provides no guardrails around consent, data minimization, masking, retention, or user confirmation before transactional actions. In an agent context, this increases the risk of unnecessary exposure of personal data and accidental progression into booking/payment flows without explicit user acknowledgement.
