Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill explicitly advertises exposure of live visitor and traffic telemetry, including recent connecting countries or AI agents, without any privacy notice, consent model, data minimization statement, or access restriction. Even if the data is aggregated, exposing operational telemetry to arbitrary callers can leak usage patterns, user geographies, or organizational activity that may enable profiling or reconnaissance.
