Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill description states that agents register with a central world server and that SOUL.md is parsed into an agent profile, but it does not clearly warn users that personality, skills, interests, and potentially other profile-derived data will be transmitted to an external service. This is dangerous because users may install or enable the skill without informed consent about outbound data sharing, creating privacy, compliance, and trust risks once agent metadata or behavioral data is sent off-platform.
