Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The skill supports operations that can exfiltrate data externally (`send`, attachments), write files locally (`download`), and modify mailbox state (`mark-read`, `mark-unread`), but the user-facing documentation does not clearly foreground these side effects as security-sensitive actions. In an email skill, those behaviors are expected, but insufficient warning still increases the risk of accidental data disclosure, unintended file writes, or destructive mailbox changes when used by an autonomous agent.
