Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly documents collection and transmission of user assessment data, session identifiers, timestamps, and optional user IDs, but provides no privacy notice, data minimization guidance, retention policy, or handling constraints. In an agent ecosystem, this can lead operators to send identifiable or behavioral data to a third-party API without understanding the privacy implications, increasing risk of unnecessary exposure and downstream misuse.
