Missing User Warnings
Medium
- Confidence
- 83% confidence
- Finding
- The skill explicitly instructs users to obtain a tenant access token with app credentials and query group message history to extract mentions, but it does not warn that this accesses potentially sensitive chat content and requires privileged credentials. In an agent-skill context, normalizing credential use and chat-history scraping without consent, scoping, or data-handling guidance increases the risk of unauthorized data access and privacy violations.
