Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill instructs the agent to access the user's mailbox and extract a single-use authentication link, which is highly sensitive authentication material. Without an explicit consent gate and a clear privacy warning that the agent may read email contents, this can normalize overbroad mailbox access and expose the user to unauthorized account access or privacy violations.
