Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill promotes generation of signed URLs that bypass normal CellCog authentication and explicitly notes they remain valid even if project access is later revoked, but it does not clearly warn users that this is an external data-sharing action. In an agent setting, this can lead to unintended disclosure of sensitive project files to other agents, tools, or humans through bearer-style links that are difficult to retract once issued.
