What problem does it solve? Encrypted content does not hide metadata: timestamps, identifiers, recipients, sizes, and notification payloads can still reveal identity, relationships, and behavior. This Skill audits that residual metadata exposure and checks whether observed behavior contradicts product privacy claims and policy statements. ## Core Features & Use Cases - Metadata Inventory and Classification: Enumerate metadata fields across APIs, storage, logs, telemetry, notifications, and third parties, then classify them as operational, avoidable, sensitive, claim-contradicting, or unknown. - Risk Mapping: Map each item to linkability, identifiability, behavioral inference, social graph exposure, and timing inference risks with explicit inference paths. - Claim and Policy Comparison: Compare observed collection, sharing, retention, and controls against marketing claims, privacy policies, and consent settings, producing MLI-prefixed findings with severity and confidence. - Use Case: An E2EE messaging product claims "we cannot see who you contact." Use this Skill to capture API traffic, inspect logs and push notification payloads, and produce an evidence-backed report showing whether contact-graph metadata is actually visible to servers or third parties. ## Quick Start Audit this service's observable metadata across API responses, logs, and push notifications, compare it against the privacy policy claims, and report findings with evidence and severity.