Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly states that agent responses, scores, and participation data are sent to and incorporated by an external service, including contribution to an anonymous population baseline, but it provides no privacy notice, consent guidance, data retention details, or warning against sending sensitive information. In an agent-skill context, this can cause operators or autonomous agents to disclose prompts, model outputs, or proprietary evaluation data to a third party without informed approval.
