Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill is explicitly designed to control a user's local Chrome session and read Outlook mailbox contents, which exposes highly sensitive personal or corporate communications. Because the description and workflow do not require a clear user-facing consent step, mailbox scope limitation, or privacy warning before accessing existing logged-in sessions, the skill can enable unintended disclosure of email content and metadata.
