Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill instructs users or agents to send user-linked data to a third-party remote service without an explicit warning at the point of submission that the content and identifier will be transmitted externally. The example includes a descriptive free-text field and a submitter identifier, which can expose identifiable or sensitive information if an agent forwards user content automatically.
