Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- The skill directs the agent to immediately connect to a third-party service, read document state, and broadcast presence as soon as a shared URL is provided. That causes external data transmission and user/activity disclosure without an explicit confirmation or warning, which can leak sensitive document access patterns and metadata to proofeditor.ai.
