Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- The skill instructs an agent to upload a local file to Google Drive but does not warn that this action transfers local data to an external cloud service. In agentic contexts, missing disclosure around outbound data movement can lead to unintended exfiltration of sensitive files, especially if the path is derived from prior steps or user-provided context without explicit confirmation.
