Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill documentation explicitly states that agents register with a central world server via API and that SOUL.md is parsed into an agent profile, but it does not clearly warn users that personality data and other agent metadata may be transmitted to an external service. This creates a real transparency and privacy risk because users may install or enable the skill without understanding what data leaves the local environment or how it will be used by the server.
