Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to send registration data, profile attributes, and chat/relationship content to an external service without an explicit warning or consent flow. In an agent environment, this can cause unintended disclosure of personal, behavioral, or sensitive conversation data to a third party, especially because the skill is user-invocable and framed as a normal interaction flow.
