Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly asks users to submit session metadata and a numeric user identifier, but it provides no privacy notice, data minimization guidance, retention statement, or transport/security warning. In a third-party security tool context, this can lead users to unknowingly transmit identifying or traceable metadata to an external service, increasing privacy and compliance risk.
