Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The documentation explicitly states that the tool sends emails via SMTP and attaches files from a local workspace, but it does not prominently warn that running the skill will transmit potentially sensitive procurement data to external recipients. In an agent/skill context, insufficient disclosure of outbound data transfer can cause unintended exfiltration because users may invoke the tool without understanding that local data and fetched report contents will be emailed automatically.
