Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs transmission of a phone number and one-time verification code to a remote API without an explicit warning that these are sensitive authentication factors. Users may not realize the agent will send both identifiers off-box, increasing privacy risk and the chance of credential interception or misuse if the endpoint is untrusted or misconfigured.
