Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The skill documents email and SMS/OTP actions that send recipient addresses, phone numbers, message contents, and verification data to an external API, but it does not warn the user that this causes third-party transmission of potentially sensitive personal data. In an agent setting, this can lead to privacy violations or unintended outbound communications because the skill normalizes high-impact actions without disclosure or consent guidance.
