Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- This skill accesses privacy-sensitive inbox, network request, and relationship context data using an API key, but it does not instruct the agent to obtain user confirmation, minimize scope, or warn that personal communications and network metadata will be retrieved. In an automation or broad-trigger setting, this can lead to silent overcollection of sensitive data and unintended exposure in summaries, logs, or downstream actions.
