Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly asks for and processes highly sensitive personal data such as name, contact information, location, LinkedIn URL, employment history, and education, but it provides no warning about privacy, retention, or safe handling of that data. Because the skill also has Write/Edit/Bash capabilities and later instructs saving outputs to disk, users may unknowingly expose PII in local files, logs, or shared workspaces.
