Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly describes capturing session tracking data and optional user identifiers, but provides no privacy notice, retention policy, minimization guidance, or handling constraints. Even though the data is not highly sensitive by itself, combining career assessment details, session IDs, timestamps, and user IDs enables profiling and linkability across requests, creating unnecessary privacy and compliance risk.
