Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly supports reading private messages, sending messages, and uploading files to an external SaaS platform but does not include any warning, consent boundary, or guidance on handling sensitive data. This creates a real privacy and data-governance risk because an agent could access or transmit confidential content to Zulip without the user clearly understanding that external communication is occurring.
