Missing User Warnings
Medium
- Confidence
- 75% confidence
- Finding
- The skill directs the agent to use a user API key to query company identity and operate on account-scoped resources, but it does not prominently require explicit user consent or warn that sensitive tenant context will be transmitted to a third-party service. This can lead to privacy surprises and inadvertent use of privileged account context beyond what the user expected.
