Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The contract explicitly sends `user_id` and arbitrary `metadata` to an external billing endpoint, but it documents no consent, minimization, or user-facing disclosure requirements. In a skill that processes user content, this creates a real privacy and compliance risk because sensitive transcript-derived or business metadata could be transmitted off-platform without the user's awareness.
