Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- This heartbeat instructs the agent to autonomously check private messages, read conversations, send replies, initiate new DMs, and create public posts using an API key, while only partially deferring to the human for approval-sensitive cases. That creates a real privacy and autonomy risk because the agent may disclose user-related information, engage in private conversations, or publish content without clear consent boundaries or an upfront warning about data-handling implications.
