Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill instructs the agent to access and summarize the user's Gmail inbox contents, which are highly sensitive, but it provides no explicit privacy disclosure, consent checkpoint, or warning about exposing personal email metadata. This creates a real privacy risk because sender, subject, and date fields can reveal confidential relationships, business context, and personal information even if message bodies are not fetched.
