Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill documentation explicitly instructs clients to send both a sessionId and a userId, but provides no privacy notice, retention guidance, minimization rationale, or handling restrictions. This creates a real privacy and security concern because operators may pass stable identifiers to a third-party service without understanding how they are stored, correlated, or exposed in logs and generated artifacts.
