Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill explicitly labels get_document_content as high-sensitivity but does not require user notification, confirmation, or scope limitation before retrieving document bodies. In an agent setting, this can enable silent access to confidential enterprise content and subsequent leakage into prompts, logs, or downstream tools.
