Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The voice-summary workflow sends generated summary text to an external TTS API without instructing the agent to warn the user or obtain consent. If the summary includes sensitive user-provided context, preferences, or proprietary information, this creates an unintended data disclosure to a third-party service.
