Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly instructs users to query product analytics data and notes that authentication is read from a locally stored credentials file, but it does not warn that the queried data may contain privacy-sensitive event properties, URLs, or user-behavior information. In an agent context, this increases the risk of overbroad querying or accidental exposure of analytics data because the capability is presented as routine and unrestricted.
