Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly collects journal content, conversation logs, and task status, then sends the generated report through external message APIs, but it provides no warning, consent step, data minimization guidance, or channel trust boundaries. This creates a real data-exfiltration/privacy risk because potentially sensitive internal context can be transmitted off-platform automatically or with only a simple trigger.
