Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill advertises broad discovery, configuration auditing, and data flow analysis that would likely inspect sensitive files, credentials, and compliance-relevant information, but it does not clearly warn users about that access or require explicit scoping and consent. In an agent context, this can lead to unintended collection or exposure of secrets, internal topology, and regulated data because users may invoke the scan without understanding how much of the environment will be inspected.
