Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly describes sending incident notifications to subscribers via email and Slack, but provides no warning that operational data will be disclosed to third parties or guidance on limiting message contents. In a status-page workflow, incident messages can easily expose internal service names, outage details, URLs, or timing information, creating unnecessary privacy and information-disclosure risk if operators follow the example as written.
