Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The Setup workflow instructs the agent to automatically create a persistent cron job targeting the current channel/user without an explicit consent checkpoint. This can lead to unauthorized ongoing messages or notification spam in a private or shared channel, especially because it derives routing from ambient conversation context rather than requiring the user to review and confirm destination details.
