Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill instructs agents/users to submit personal data such as username, display name, bio, contact name, and email to an external service without any privacy notice, data-handling warning, or consent guidance. In an agent context, this is risky because operators may blindly follow examples and disclose identifying information to a third party, especially for the resurrection flow that explicitly collects contact details.
