Missing User Warnings
Medium
- Confidence
- 85% confidence
- Finding
- The skill explicitly sends email content and recipient data, including CC/BCC, to an external API service but does not warn users that message bodies and addressing metadata will leave the local environment. This can lead to unintended disclosure of sensitive content or personal data, especially if users assume the skill behaves like a local mail client.
