Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The skill instructs the agent to create an event JSON containing user requests, candidate actions, and potentially private account, billing, payment, or personal data, but it provides no minimization, consent, retention, redaction, or disclosure guidance. In an agent workflow, this can normalize copying sensitive data into local files and secondary tooling, increasing the risk of unnecessary exposure, logging, or downstream mishandling.
