Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly advertises capabilities to read/send Gmail, modify Calendar, write Sheets, manage Drive, and send Chat messages, but it does not provide clear safety guidance about external side effects, data sensitivity, authorization scope minimization, or requiring explicit user confirmation before destructive or privacy-impacting actions. In an agent setting, these are real-world operations against a live Workspace tenant, so omission of warnings increases the risk of unintended data modification, data disclosure, or outbound communications.
