Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The sample request includes persistent identifiers such as sessionId and userId along with detailed career assessment data, but the skill provides no privacy notice, data minimization guidance, retention policy, or warning that this information is sent to a third-party API. In an agent skill context, this can lead to unnecessary disclosure of personal or profile data to an external service without informed consent or clear handling expectations.
