Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- This skill exposes highly sensitive inbox data, including OTPs, verification links, phone numbers, email addresses, and full message bodies, but the description and notes do not prominently warn users about the sensitivity of this content. That omission increases the risk of accidental disclosure, unsafe logging, or misuse by downstream agents and operators, especially because the examples explicitly show OTP extraction and full-content retrieval.
