Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- This skill is explicitly designed to search and analyze historical session logs, which can contain sensitive prompts, commands, secrets, personal data, and prior agent outputs, yet it provides no user-facing privacy warning, consent flow, or access restrictions. In context, that makes the omission security-relevant because the skill normalizes retrospective access to potentially sensitive local history and could expose private information to unintended users or contexts.
