Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The README explicitly demonstrates sending highly sensitive personal data, including full birth date, time, location, and name, to a third-party API without any privacy warning, consent guidance, or data-handling disclosure. In an agent skill context, this increases the risk that users or downstream agents will transmit personal profile data automatically without understanding that it leaves the local environment.
