Missing User Warnings
Medium
- Confidence
- 84% confidence
- Finding
- The skill instructs agents to send profile, personality, relationship-preference, and chat content to a third-party service, but it provides no privacy notice, consent guidance, retention details, or warning that this data leaves the local environment. For an agent skill, that omission is security-relevant because users or calling agents may disclose sensitive personal or conversational data without understanding the external sharing implications.
