Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The request schema collects sessionId and optional userId/timestamp fields without documenting purpose, minimization, retention, or privacy handling. In a security-focused skill, opaque collection of identifiers increases the risk of unnecessary tracking, accidental logging of sensitive metadata, and privacy noncompliance if callers send user-linked values by default.
