Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill documentation explicitly includes transmission of `sessionId`, `userId`, and timestamped assessment data to a third-party API without any statement about data minimization, retention, access controls, or privacy handling. Even if the fields are not highly sensitive by themselves, they can enable correlation of user activity and organizational assessment records, which is risky in a security-assessment context where metadata may reveal internal posture or customer identity.
