Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill explicitly advertises API-key-backed admin operations that can modify project state and send data to external VoteShip services, but it does not clearly warn the user that invoking these tools may transmit potentially sensitive business/customer data or make account-level changes. In an agent setting, that omission increases the chance of unintended writes, data disclosure, or risky automation using a highly privileged credential.
