Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill enables sending message bodies and attachments to an external SMTP service, but the description does not prominently warn users that local content will leave the environment and be transmitted to a third-party mail provider. In an agent setting, this omission can lead to accidental exfiltration of sensitive text or files because users may not realize the external transmission boundary.
