Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill explicitly states it pulls live QBO financial data and reads client SOP files, but it does not require any explicit authorization check, consent prompt, or warning that sensitive financial data and internal client documentation will be accessed. In an agent setting, that increases the risk of over-collection or unintended disclosure of confidential business information if the skill is triggered too casually or for the wrong client context.
