Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly supports sending outreach emails and follow-up messages to external vendors, but the skill metadata and workflow do not warn users that it may initiate external communications on their behalf. This creates a meaningful risk of unintended outbound contact, privacy leakage, or reputational harm if the agent sends messages without clear user awareness, review, or confirmation.
