Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The webhook section explicitly states that full message payloads, including `body`, sender/recipient identifiers, and names, are POSTed to external URLs, but it does not clearly warn that this forwards private DM contents to third-party infrastructure. In an agent-messaging skill, users may reasonably assume messages remain within the platform unless prominently told otherwise, so this omission can lead to inadvertent disclosure of sensitive data to webhook providers, logs, or misconfigured endpoints.
