Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly reads project STATUS.md content and sends derived context to Telegram via the Bot API, but the description does not clearly warn users that potentially sensitive project state will be transmitted to an external service. This can cause unintended disclosure of internal project details, blockers, or operational context to chats or recipients the user did not fully understand were involved.
