Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs the agent to connect to a third-party chat server, fetch room history, and send messages, but it provides no user-facing warning or consent step about external data sharing. In an agent setting, this creates a real risk that prompts, derived context, or user-related content could be transmitted to an external service or that untrusted chat content could be ingested back into the agent workflow.
