Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly documents sending audit session identifiers, timestamps, and a numeric userId to an external audit-processing API without any warning that these values may be sensitive operational metadata. In a security-audit context, this data can reveal internal assessment cadence, user linkage, and compliance activities, which increases privacy and reconnaissance risk if users submit real identifiers.
