Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The code forwards inbound channel message content plus user metadata (channel ID, message ID, username, user ID, timestamp) to the MCP client via notifications. That is a real privacy and data-exposure concern because the tool acts as a bridge from an external service into the local MCP consumer without any consent check, minimization, or visible disclosure in this file.
