Missing User Warnings
Medium
- Confidence
- 83% confidence
- Finding
- The skill explicitly instructs the agent to read mailbox credentials from a local secrets.json file, but it does not require any user-facing disclosure or runtime confirmation that credentials will be accessed and used for login. In an agentic environment, silent credential use is a meaningful security and privacy risk because it enables account access without clear, contextual consent each time the skill runs.
