Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill directs agents to send user-provided phone numbers to public third-party lookup services, but it does not clearly warn the user that their phone number will be transmitted off-platform. Phone numbers are personal data, and silent disclosure to external services creates privacy and compliance risk even if the endpoint is legitimate.
