Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill advertises a send_sms capability but provides no warning that message contents and destination phone numbers will be transmitted to an external service, may incur per-message charges, and may create privacy, compliance, or abuse risks. In an agent context, a user may not realize that invoking this tool can contact third parties in the real world, making the omission materially dangerous even if the capability is legitimate.
