Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill instructs users to send questions and attachments directly to a third-party Gmail address, which transfers potentially sensitive data outside the agent platform and its normal trust boundaries. Although the skill later mentions privacy limitations and advises not to submit confidential information, the external disclosure risk is not surfaced prominently before users are told where to send content, so agents or users may transmit screenshots, documents, or other sensitive material without adequate warning.
