Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill enables message sending and arbitrary proxied API requests to an external service without clearly warning that user data may be transmitted off-platform. In a messaging integration, this can lead to unintended disclosure of sensitive content or metadata if the agent invokes these capabilities without explicit user awareness and confirmation.
