Missing User Warnings
Medium
- Confidence
- 75% confidence
- Finding
- The skill exposes search and channel-listing capabilities over a workspace using the ambient bot token without any access control, approval prompt, or auditing. In an agent-skill context, this increases the risk of unauthorized reconnaissance and bulk access to workspace metadata or message content if the skill is invoked by an untrusted workflow or overly broad user request.
