Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill description explicitly states that agents register with a world server and that SOUL.md is parsed into an agent profile, but it does not disclose what data leaves the local environment, how it is used, or what privacy/security controls apply. Because SOUL.md may contain sensitive behavioral instructions, identity traits, or operational context, sending it or derived profile data to a centralized service can create privacy leakage and profiling risks without informed user consent.
