Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly collects sessionId, userId, and timestamp metadata but provides no privacy notice, retention limits, purpose limitation, or handling guidance. In a third-party API context, these identifiers can enable user/session tracking and linkage of operational activity, creating unnecessary privacy and audit-risk exposure if logged, shared, or retained insecurely.
