Missing User Warnings
Medium
- Confidence
- 85% confidence
- Finding
- The skill requests userId, sessionId, timestamps, and assessment responses but provides no privacy notice, retention policy, minimization guidance, or handling constraints. Even if these fields are not inherently secret, they can become sensitive when tied to organizational governance posture and user activity, creating unnecessary exposure and compliance risk when sent to a third-party service.
