Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly describes collecting and transmitting detailed organizational assessment data along with session identifiers, timestamps, and optional user identifiers, but provides no privacy notice, retention limits, access controls, or data-handling constraints. In a security-focused product, this is particularly sensitive because the submitted systems, tools, posture, and industry data could help an attacker profile the organization's defenses if mishandled or exposed.
