Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill includes ready-made queries that retrieve personally identifiable information such as names, email addresses, and phone numbers for trainees and trainers, but provides no privacy constraints, authorization checks, or output-minimization guidance. In an agent setting, this increases the chance of over-collection or disclosure of sensitive training-management data to users who may not be entitled to receive it.
