Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The webhook feature forwards full message contents, including subject and body, to an arbitrary external URL, but the skill provides no privacy warning, trust boundary discussion, or guidance on securing webhook destinations. This can cause sensitive email content to be exfiltrated to third-party infrastructure unintentionally, especially if agents configure untrusted or misconfigured endpoints.
