Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The skill is explicitly designed to enumerate documents, list pages, and export page contents from a remote Coda workspace, but it does not warn users that running these commands will transmit requests to Coda and may expose sensitive organizational data to the agent or downstream systems handling the output. In an agent context, this increases the chance of over-collection and unintended disclosure of private workspace content, especially when markdown/json/html exports are consumed automatically.
