Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill documentation asks users to provide an `INTERCOM_ACCESS_TOKEN` and exposes actions that retrieve conversation data, but it does not clearly disclose that the skill will access potentially sensitive customer support content from Intercom. This creates a transparency and consent problem: users may supply a high-privilege token without understanding the scope of data access, increasing the risk of unintended exposure of customer messages and related metadata.
