Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The webhook section encourages sending click and link event data to arbitrary external endpoints without warning that these payloads may contain user interaction metadata, referral context, or other sensitive operational data. In an agent skill context, omission of a consent/privacy warning can cause unreviewed exfiltration of usage data to third-party infrastructure.
