Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to collect detailed organizational profile, compliance, tooling, and challenge data and send it to an external API, but it does not require explicit user consent, data minimization, or a clear disclosure that this information leaves the local environment. Because the data concerns privacy posture and business operations, unintended transmission could expose sensitive internal information to a third party and create confidentiality or compliance issues.
