Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly instructs sending a login URL over third-party messaging channels without warning that the link is a sensitive authentication artifact. If intercepted, forwarded, or previewed by another party or service, the recipient could complete the login flow and gain unauthorized access.
