Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill explicitly states that agents register with a central world server and that SOUL.md is parsed into an agent profile, but it does not disclose what specific data is transmitted, whether prompts/personality data are exposed, or what consent and access controls apply. In a social simulation context, SOUL.md and derived profile data may contain sensitive behavioral instructions, private preferences, or operational metadata, so undocumented sharing creates meaningful privacy and security risk.
