Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly handles customer personal and business data, including names, WeChat IDs, email addresses, budgets, contact history, and deal status, yet it provides no privacy warning, consent guidance, retention limits, or notice that outputs may expose sensitive records. In a CRM context, this increases the risk of unauthorized collection, disclosure, or mishandling of personal data through normal use of the skill.
