Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill exposes multiple destructive and state-changing Google Classroom operations such as course creation, deletion, updates, invitation acceptance, and registration management, but it does not provide an explicit warning that these actions can permanently change user or organizational data. In an agent setting, this increases the risk of accidental misuse, unsafe automation, or social engineering prompts leading to unintended changes, especially because the skill encourages command discovery and execution without requiring confirmation for high-impact actions.
