Missing User Warnings
Medium
- Confidence
- 89% confidence
- Finding
- The skill advertises handling highly sensitive assets including email inboxes, phone verification, CAPTCHA solving, passwords, TOTP secrets, API keys, and identity management, but provides no user-facing warnings about security boundaries, consent, lawful use, data minimization, or the risks of exposing credentials and verification channels. In this context, omission is dangerous because agents may be granted broad access to identity and account infrastructure without clear safeguards, increasing the likelihood of credential leakage, account takeover, unauthorized automation, or abuse of third-party services.
