Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to send pitch decks and conduct staged outreach to external investors without any safeguards around user consent, authorization, confidentiality, or data minimization. In an agent setting, this can lead to unintended disclosure of sensitive startup materials, business plans, metrics, or founder contact details to third parties, creating privacy, confidentiality, and reputational risk.
