Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The README directs the agent to collect sensitive personal and family information as part of a calibration workflow, but it does not provide any privacy notice, data-minimization guidance, consent language, or handling restrictions. In an agent setting, this can normalize oversharing of intimate background data and lead to unnecessary retention, downstream reuse, or exposure of sensitive user attributes.
