Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to create guest-access production sheets and expose a shareable `guest_code`/URL without requiring an explicit user warning about the public or bearer-token nature of that link. Anyone who obtains the link can likely view the production sheet and generated outputs, which can expose user-supplied design parameters or proprietary CAD artifacts.
