Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill documents outbound email and SMS OTP capabilities that can trigger real-world external actions, but it provides no warning about consent, privacy, cost, or the need for explicit user confirmation before sending. In an agent context, this increases the risk of unauthorized messaging, spam, privacy violations, and accidental account-verification actions.
