Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill explicitly states that a OneDrive file will be downloaded and then uploaded to transit storage, but it provides no warning that data is being copied to another storage location or that sensitive content may leave its original trust boundary. This can cause unintended disclosure of private or regulated data, especially if users assume the action only reads directly from OneDrive rather than staging a copy elsewhere.
