Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The skill documentation explicitly supports sending local files and URL-sourced attachments to external Zalo recipients, but it does not clearly warn users that invoking the skill will transmit local data off-host. In an agent setting, this omission increases the risk of accidental data exfiltration, especially if users provide broad file paths or do not realize remote URLs may be fetched and forwarded.
