Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The skill instructs the agent to auto-detect and pass channel and chatId from session context into reminder creation without an explicit user-facing disclosure or confirmation. This creates a privacy and consent risk because reminders may be scheduled against a communication destination the user did not knowingly approve, and exposes internal routing identifiers to downstream tooling.
