Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill enables sensitive analytics operations including user lookup, retrieval of individual activity histories, user property mutation, event ingestion, and cohort membership changes, but it provides no privacy, authorization, or data-minimization guidance. In practice, this can normalize access to personal behavioral data and allow an agent to expose, modify, or bulk-process user information without explicit user confirmation or scope checks.
