Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill documentation explicitly encourages submission of organizational assessment data along with tracking identifiers such as sessionId, userId, and timestamps, but provides no privacy notice, retention policy, minimization guidance, or warning about handling potentially sensitive business metadata. In a security-focused product, this context makes the omission more concerning because the collected data can reveal security posture, compliance scope, deployment model, and vendor-selection priorities that are valuable for profiling or targeting an organization.
