Missing User Warnings
Medium
- Confidence
- 76% confidence
- Finding
- The skill establishes a live connection to an external SQL Server and retrieves data without any user-facing disclosure or consent mechanism. In an agent/skill context, undisclosed outbound network/database access can surprise operators, expand the trust boundary, and expose sensitive business data if the skill is invoked in environments where users do not expect external data access.
