Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly collects identifiable and potentially sensitive organizational data such as organization name, government affiliation, contact email, user ID, session IDs, timestamps, role, and department, but provides no privacy notice, data minimization guidance, retention policy, or handling constraints. In a cybersecurity-planning context, this metadata can reveal sensitive operational details and create unnecessary exposure if logged, retained, shared with third parties, or breached.
