Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly advertises actions that can contact HR on the user's behalf, but it does not clearly warn that these are external, account-linked communications that may be irreversible or socially consequential. Because it reuses an authenticated Chrome session on zhipin.com, invoking these commands can send real messages from the user's account and create unintended outreach if the user misunderstands the automation.
