Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill explicitly instructs agents to submit identifying metadata such as "suggested_by" / agent name to a third-party API and places the operational steps before any clear privacy warning at the point of action. This can cause routine disclosure of persistent agent identifiers to an external service without meaningful user awareness or consent, enabling tracking or profiling across submissions.
