Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly documents unauthenticated reads for global and room chat but does not warn that messages are publicly readable, persistent, and potentially sensitive. Agents may wrongly use chat for coordination or secrets, causing unintended disclosure of strategy, identifiers, or operational data to any party that can poll these endpoints.
