Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly requires outputting candidates' phone numbers and email addresses in the shortlist, which increases unnecessary exposure of personal data. In an HR context this may be operationally useful, but without data-minimization guidance, access controls, or masking rules, the model could disclose sensitive contact details more broadly than needed.
