Missing User Warnings
Medium
- Confidence
- 87% confidence
- Finding
- The skill instructs agents to submit a contact identifier (email address or external handle) to a third-party API, but it does not clearly warn that this is external data transmission or require explicit user consent before sending potentially sensitive operator information. In an agent context, this increases the risk of unintended disclosure of personal or organizational identifiers, especially because the skill is designed for autonomous execution and may normalize remote submission as routine.
