Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly handles uploaded medical reports containing highly sensitive personal health information, but it provides no privacy notice, minimization guidance, retention limits, or instructions for safe handling of that data. In a health-related context, this increases the risk of unnecessary exposure, over-collection, or improper downstream sharing of personal data, even if the omission appears accidental rather than malicious.
