Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs the agent to collect detailed organizational security-control maturity data and send it to a third-party API, but it does not require an explicit user warning or consent before transmission. Because this data describes internal security posture and gaps, sending it externally can expose sensitive operational details and create privacy, confidentiality, and supply-chain risk.
