Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly supports outreach and autonomous modes that draft and send external messages, and it writes campaign artifacts such as outbox messages, reports, logs, and state files, but it does not clearly require explicit user confirmation, dry-run behavior, or prominent warnings about external side effects. In an agent setting, this can lead to unauthorized communications, spam, reputational harm, and unintended modification of campaign data on disk, especially because the skill is user-invocable and presented as an entry point for all campaign operations.
