Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The runbook explicitly recommends `delivery.mode = "webhook"` for scheduled runs that call an external HTTP endpoint, but it does not instruct the agent to warn the user or confirm consent before transmitting data outside the chat system. In a scheduling skill, this omission is meaningful because future agent runs may send summaries, context, or operational data to third-party services, creating a risk of unintended data exfiltration or privacy violations.
