Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill documents an optional `user_id` parameter that is sent to an external third-party API but does not disclose the privacy implication that an end-user identifier will leave the local system. This can cause unintended transmission of personal or correlatable identifiers to Zhipu, creating privacy, compliance, and user-consent risks.
